PT-2024-8975 · Cisco · Managed C-Series+2
Published
2024-10-02
·
Updated
2024-10-08
·
CVE-2024-20365
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco UCS B-Series, Managed C-Series, and X-Series Servers (affected versions not specified)
Description:
The issue is related to insufficient input validation in the Redfish API, allowing an authenticated, remote attacker with administrative privileges to perform command injection attacks and elevate privileges to root. This can be achieved by sending crafted commands through the Redfish API on an affected device. The vulnerability is due to the lack of proper measures to neutralize special elements.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ucs B-Series
Managed C-Series
X-Series Servers