Improper Privilege Management in Cisco Integrated Management Controller - CVE-2020-26063

 

Improper Privilege Management in Cisco Integrated Management Controller - CVE-2020-26063

Published: November 5, 2020


Vulnerability identifier: #VU48158
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-26063
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper authorization checks on API endpoints. A remote authenticated attacker can send malicious requests to an API endpoint and download files or modify limited configuration options on the affected system.


Affected software

Cisco Integrated Management Controller

How to mitigate CVE-2020-26063

Install updates from vendor's website.

Cisco Integrated Management Controller - addressed in versions 4.1.2b IMC, 4.1.2b UCSM

External References

Related Security Bulletins