Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20356

Опубликовано: 24 апр. 2024
Источник: nvd
CVSS3: 8.7
EPSS Средний

Описание

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to elevate their privileges to root.

EPSS

Процентиль: 97%
0.33574
Средний

8.7 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.7
github
почти 2 года назад

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to elevate their privileges to root.

CVSS3: 8.7
fstec
почти 2 года назад

Уязвимость веб-интерфейса управления средства удалённого администрирования серверов Cisco Integrated Management Controller (IMC), позволяющая нарушителю повысить свои привилегии до уровня root

EPSS

Процентиль: 97%
0.33574
Средний

8.7 High

CVSS3

Дефекты

CWE-78