CVE-2026-20094
CVSS 8.8 HIGH: a vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with…
Vulnerabilità · 180 giorni fa
Cisco Integrated Management Controller (IMC) has three separate command injection vulnerabilities (CVE-2026-20094, CVE-2026-20095, CVE-2026-20096) in its web-based management interface. These flaws allow authenticated attackers, including those with only read-only access, to execute arbitrary commands as the root user on the underlying operating system.
This elevates the risk because limiting user roles does not prevent full system compromise. There are no workarounds; only Cisco's software updates fix the issue. Organizations with IMC exposed to administrative networks or third-party access face heightened risk and must prioritize patching immediately.
CVSS 8.8 HIGH: a vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with…
CVSS 6.5 MEDIUM: a vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with…
CVSS 6.5 MEDIUM: a vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with…
3 fonti che coprono questa storia
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
Cisco patches two 9.8 CVSS flaws (CVE-2026-20093, CVE-2026-20160), preventing authentication bypass and root access.
Cisco Patches Critical and High-Severity Vulnerabilities
The bugs could lead to authentication bypass, remote code execution, information disclosure, and privilege escalation.
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access.
Cisco Security Advisory: Cisco Integrated Management Controller Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary code or commands on the underlying operating system of an affected system and elevate privileges to root.
Part of the PlainSec briefing for 2026-04-03