Cisco Integrated Management Controller Vulnerability Allows Unauthorized Actions
CVE-2020-26063
5.4MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 18 November 2024
Summary
A vulnerability exists within the API endpoints of Cisco Integrated Management Controller, enabling authenticated, remote attackers to bypass authorization mechanisms. This weakness stems from inadequate authorization checks on the API endpoints, permitting attackers to send crafted malicious requests. Exploitation of this vulnerability potentially allows attackers to download sensitive files or modify specific configuration settings on the compromised system. It is critical to note that there are currently no available workarounds to mitigate this risk.
Affected Version(s)
Cisco Unified Computing System (Managed) 4.0(1a)
Cisco Unified Computing System (Managed) 3.2(3n)
Cisco Unified Computing System (Managed) 4.1(1a)
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved