CyberzSOC

Publication detail
← Back to advisories & guidance

2024-042: Vulnerability in Cisco Integrated Management Controller ↗ source

April 18, 2024 CERT-EU Advisory

Summary

The vulnerability CVE-2024-20356 [2], with a CVSS score of 8.7, could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to elevate their privileges to root. The vulnerability CVE-2024-20295 [3], with a CVSS score of 8.8, could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-20295 8.8 High Cisco Cisco Unified Computing System (Standalone) A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command inject…
CVE-2024-20356 8.7 High Cisco Cisco Unified Computing System (Standalone) A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker w…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.