PT-2020-4665 · Cisco · Cisco Integrated Management Controller

Leonidas Tsaousis

+1

·

Published

2020-11-04

·

Updated

2024-11-18

·

CVE-2020-26063

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Integrated Management Controller (affected versions not specified)
Description A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization. The issue is due to improper authorization checks on API endpoints, allowing an attacker to send malicious requests to an API endpoint. This could enable the attacker to download files from or modify limited configuration options on the affected system. Additionally, the vulnerability may allow a remote attacker to determine all existing usernames.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2020-05217
CVE-2020-26063

Affected Products

Cisco Integrated Management Controller