Security VulnerabilitiesNews

Cisco Integrated Management Controller Web-Based Management Interface Command Injection Vulnerability [CVE-2024-20356]

CVE number = CVE-2024-20356

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root.

This vulnerability is due to insufficient user input validation.

An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software.

A successful exploit could allow the attacker to elevate their privileges to root.

Cisco has released software updates that address this vulnerability.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-bLuPcb

Kerry Dean

Kerry is a Content Creator at www.systemtek.co.uk she has spent many years working in IT support, her main interests are computing, networking and AI.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.