Lucene search

K
ciscoCiscoCISCO-SA-UCS-API-RCE-UXWPEDHD
HistoryNov 18, 2020 - 4:00 p.m.

Cisco Integrated Management Controller Multiple Remote Code Execution Vulnerabilities

2020-11-1816:00:00
tools.cisco.com
41
cisco
imc
api
remote code execution
vulnerabilities
buffer overflow
root privileges
software updates
ciscosecurityadvisory
http request
operating system
exploitable

EPSS

0.002

Percentile

58.3%

Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges.

The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-api-rce-UXwpeDHd [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-api-rce-UXwpeDHd”]

Affected configurations

Vulners
Node
ciscounified_computing_systemMatchany
OR
ciscounified_computing_system_softwareMatchany
OR
ciscounified_computing_systemMatchany
OR
ciscounified_computing_system_softwareMatchany
VendorProductVersionCPE
ciscounified_computing_systemanycpe:2.3:h:cisco:unified_computing_system:any:*:*:*:*:*:*:*
ciscounified_computing_system_softwareanycpe:2.3:a:cisco:unified_computing_system_software:any:*:*:*:*:*:*:*

EPSS

0.002

Percentile

58.3%

Related for CISCO-SA-UCS-API-RCE-UXWPEDHD