Cisco Integrated Management Controller Vulnerability Allows Unauthorized Actions
CVE-2020-26063
5.4MEDIUM
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 18 November 2024
What is CVE-2020-26063?
A vulnerability exists within the API endpoints of Cisco Integrated Management Controller, enabling authenticated, remote attackers to bypass authorization mechanisms. This weakness stems from inadequate authorization checks on the API endpoints, permitting attackers to send crafted malicious requests. Exploitation of this vulnerability potentially allows attackers to download sensitive files or modify specific configuration settings on the compromised system. It is critical to note that there are currently no available workarounds to mitigate this risk.
Affected Version(s)
Cisco Unified Computing System (Managed) 4.0(1a)
Cisco Unified Computing System (Managed) 3.2(3n)
Cisco Unified Computing System (Managed) 4.1(1a)