Vulnerabilità ed exploit · Attacco ad app web
Cisco IMC Command Injection Lets Read-Only Users Execute as Root Cisco Integrated Management Controller (IMC) has three separate command injection vulnerabilities (CVE-2026-20094 , CVE-2026-20095 , CVE-2026-20096 ) in its web-based management interface. These flaws allow authenticated attackers, including those with only read-only access, to execute arbitrary commands as the root user on the underlying operating system.
This elevates the risk because limiting user roles does not prevent full system compromise. There are no workarounds; only Cisco's software updates fix the issue. Organizations with IMC exposed to administrative networks or third-party access face heightened risk and must prioritize patching immediately.
3 fonti · 2 apr
CVE-2026-20094 NVD KEV
CVSS 8.8 HIGH: a vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with…
CVE-2026-20095 NVD KEV
CVSS 6.5 MEDIUM: a vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with…
CVE-2026-20096 NVD KEV
CVSS 6.5 MEDIUM: a vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with…
Cronologia Fonti 2 apr The Hacker News
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
Cisco patches two 9.8 CVSS flaws (CVE-2026-20093, CVE-2026-20160), preventing authentication bypass and root access.
originale 2 apr SecurityWeek
Cisco Patches Critical and High-Severity Vulnerabilities
The bugs could lead to authentication bypass, remote code execution, information disclosure, and privilege escalation.
originale 2 apr Cisco PSIRT
Cisco Security Advisory: Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access.
originale Riepilogo fornitore: Cisco
Part of the PlainSec briefing for 2026-04-03
Every edition of this story: Cisco IMC Command Injection Lets Read-Only Users Execute as Root
Altro da oggi
Vulnerabilità ed exploit · Attacco ad app web
Cisco IMC Command Injection Lets Read-Only Users Execute as Root Cisco Integrated Management Controller (IMC) has three separate command injection vulnerabilities (CVE-2026-20094 , CVE-2026-20095 , CVE-2026-20096 ) in its web-based management interface. These flaws allow authenticated attackers, including those with only read-only access, to execute arbitrary commands as the root user on the underlying operating system.
This elevates the risk because limiting user roles does not prevent full system compromise. There are no workarounds; only Cisco's software updates fix the issue. Organizations with IMC exposed to administrative networks or third-party access face heightened risk and must prioritize patching immediately.
3 fonti · 2 apr
CVE-2026-20094 NVD KEV
CVSS 8.8 HIGH: a vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with…
CVE-2026-20095 NVD KEV
CVSS 6.5 MEDIUM: a vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with…
CVE-2026-20096 NVD KEV
CVSS 6.5 MEDIUM: a vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with…
Cronologia Fonti 2 apr The Hacker News
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
Cisco patches two 9.8 CVSS flaws (CVE-2026-20093, CVE-2026-20160), preventing authentication bypass and root access.
originale 2 apr SecurityWeek
Cisco Patches Critical and High-Severity Vulnerabilities
The bugs could lead to authentication bypass, remote code execution, information disclosure, and privilege escalation.
originale 2 apr Cisco PSIRT
Cisco Security Advisory: Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access.
originale Riepilogo fornitore: Cisco
Part of the PlainSec briefing for 2026-04-03
Every edition of this story: Cisco IMC Command Injection Lets Read-Only Users Execute as Root
Altro da oggi