Command injection in Cisco Integrated Management Controller - CVE-2018-0430
Published: September 5, 2018 / Updated: September 7, 2018
Cisco Integrated Management Controller
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.
The vulnerability exists in the web-based management interface of Cisco Integrated Management Controller (IMC) Software due to insufficient validation of command input. A remote attacker can send specially crafted commands to the web-based management interface to inject and execute arbitrary, system-level commands with root privileges.