PT-2020-4960 · Cisco · Cisco Integrated Management Controller

Abramov Nikita

+1

·

Published

2020-11-18

·

Updated

2021-08-06

·

CVE-2020-3470

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Integrated Management Controller (IMC) (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) that could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. These vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system, potentially leading to an exploitable buffer overflow condition. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05535
CVE-2020-3470

Affected Products

Cisco Integrated Management Controller