ZeroHour
Cisco Security Advisoriespublished ()ingested

Cisco Integrated Management Controller Argument Injection Vulnerabilities

highAdvisoryimportance 28
AI summary · glm-5.3

Cisco patched multiple argument-injection vulnerabilities in Cisco IMC's web management interface allowing authenticated attackers root command execution.

Cisco published an advisory covering multiple argument injection vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC). An authenticated, remote attacker could exploit them to execute arbitrary commands on the underlying operating system and elevate privileges to root. Cisco released software updates and states there are no workarounds; the advisory carries a High Security Impact Rating.

  • Argument injection in Cisco IMC web management interface
  • Authenticated remote attacker can gain root command execution
  • Software updates released; no workarounds available
  • Security Impact Rating: High
Full article

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU Security Impact Rating: High CVE:…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.