PT-2024-8975 · Cisco · Managed C-Series +2

Published

2024-10-02

·

Updated

2024-10-08

·

CVE-2024-20365

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C

Name of the Vulnerable Software and Affected Versions:

Cisco UCS B-Series, Managed C-Series, and X-Series Servers (affected versions not specified)

Description:

The issue is related to insufficient input validation in the Redfish API, allowing an authenticated, remote attacker with administrative privileges to perform command injection attacks and elevate privileges to root. This can be achieved by sending crafted commands through the Redfish API on an affected device. The vulnerability is due to the lack of proper measures to neutralize special elements.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-10657
CVE-2024-20365

Affected Products

Cisco Ucs B-Series
Managed C-Series
X-Series Servers