Количество 3
Количество 3
CVE-2026-20093
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user.
GHSA-8gpv-wqhx-xp52
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user.
BDU:2026-04536
Уязвимость функции смены пароля средства удалённого администрирования серверов Cisco Integrated Management Controller (IMC), позволяющая нарушителю обойти существующие механизмы безопасности и повысить свои привилегии до уровня admin
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-20093 A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user. | CVSS3: 9.8 | 1% Низкий | 4 месяца назад | |
GHSA-8gpv-wqhx-xp52 A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user. | CVSS3: 9.8 | 1% Низкий | 4 месяца назад | |
BDU:2026-04536 Уязвимость функции смены пароля средства удалённого администрирования серверов Cisco Integrated Management Controller (IMC), позволяющая нарушителю обойти существующие механизмы безопасности и повысить свои привилегии до уровня admin | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад |
Уязвимостей на страницу