Vulnerabilità ed exploit · Attacco ad app web
Cisco Security Advisory: Cisco Integrated Management Controller Authentication Bypass Vulnerability A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
4 fonti · 3 apr
Cronologia Fonti 3 apr Help Net Security
Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093) - Help Net Security
Cisco has fixed CVE-2026-20093, a critical authentication bypass flaw in its Integrated Management Controller (IMC).
originale 2 apr CSO Online
Cisco fixes critical IMC auth bypass present in many products
The Integrated Management Controller (IMC) flaw gives attackers admin access and remote control over servers even when main OS is shut down.
originale 2 apr BleepingComputer
Critical Cisco IMC auth bypass gives attackers Admin access
Cisco has patched several critical and high-severity vulnerabilities, including an Integrated Management Controller (IMC) authentication bypass that enables attackers to gain Admin access.
originale Riepilogo fornitore: Cisco
Part of the PlainSec briefing for 2026-04-03
Every edition of this story: Cisco Security Advisory: Cisco Integrated Management Controller Authentication Bypass Vulnerability
Altro da oggi
Vulnerabilità ed exploit · Attacco ad app web
Cisco Security Advisory: Cisco Integrated Management Controller Authentication Bypass Vulnerability A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
4 fonti · 3 apr
Cronologia Fonti 3 apr Help Net Security
Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093) - Help Net Security
Cisco has fixed CVE-2026-20093, a critical authentication bypass flaw in its Integrated Management Controller (IMC).
originale 2 apr CSO Online
Cisco fixes critical IMC auth bypass present in many products
The Integrated Management Controller (IMC) flaw gives attackers admin access and remote control over servers even when main OS is shut down.
originale 2 apr BleepingComputer
Critical Cisco IMC auth bypass gives attackers Admin access
Cisco has patched several critical and high-severity vulnerabilities, including an Integrated Management Controller (IMC) authentication bypass that enables attackers to gain Admin access.
originale Riepilogo fornitore: Cisco
Part of the PlainSec briefing for 2026-04-03
Every edition of this story: Cisco Security Advisory: Cisco Integrated Management Controller Authentication Bypass Vulnerability
Altro da oggi