CVE-2012-5417

CRITICAL

Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which allows remote attackers to execute arbitrary comman...

Affects 1 product across 1 vendor.

BCS7.71
CVSS 2.010.0
EPSS3.1%
Percentile87th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-264: Permissions, Privileges, and Access Controls

Broad class covering failures in permission enforcement. Deprecated in favor of CWE-284, CWE-862, CWE-863.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2012. A critical vulnerability affects Cisco systems (CVE-2012-5417). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2012-GLOBAL-092485-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2012-5417?
This vulnerability was disclosed in 2012. A critical vulnerability affects Cisco systems (CVE-2012-5417). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2012-5417?
CVE-2012-5417 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 3.1%.
Is CVE-2012-5417 actively exploited?
No confirmed active exploitation of CVE-2012-5417 as of 2026-05-30.
How do I remediate CVE-2012-5417?
Priority: MEDIUM. Advisory: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-dcnm PSIRT: [email protected]
What systems are affected by CVE-2012-5417?
CVE-2012-5417 affects: Cisco.
Vulnerability Details
CVE IDCVE-2012-5417
BSIDBS-2012-GLOBAL-092485-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2012-11-02
Last Modified2026-04-29
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which allows remote attackers to execute arbitrary commands via JBoss Application Server Remote Method Invocation (RMI) services, aka Bug ID CSCtz44924.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which allows remote attackers to execute arbitrary commands via JBoss Application Server Remote Method Invocation (RMI) services, aka Bug ID CSCtz44924. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Prime Data Center Network Manager
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 5020 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash4b7cab09bbe7efd1e21198b34d98f0eeaa536ffb517fa8890c582b577015140dd75bd6b6324a097bfa5d1987716659fb2bffaee95a0e33ba94502515fc547d57
Related CVEs affecting Cisco
CVE-2000-1055 10.0 Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote at... CVE-2004-0391 10.0 Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solutio... CVE-2007-5580 10.0 Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.... CVE-1999-0775 10.0 Cisco Gigabit Switch routers running IOS allow remote attackers to forward un... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →