Vulnerabilità · 179 giorni fa
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
4 fonti che coprono questa storia
Cisco has fixed CVE-2026-20093, a critical authentication bypass flaw in its Integrated Management Controller (IMC).
Cisco fixes critical IMC auth bypass present in many products
The Integrated Management Controller (IMC) flaw gives attackers admin access and remote control over servers even when main OS is shut down.
Critical Cisco IMC auth bypass gives attackers Admin access
Cisco has patched several critical and high-severity vulnerabilities, including an Integrated Management Controller (IMC) authentication bypass that enables attackers to gain Admin access.
Cisco Security Advisory: Cisco Integrated Management Controller Authentication Bypass Vulnerability
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin.
Part of the PlainSec briefing for 2026-04-03