Improper Privilege Management in Cisco Integrated Management Controller - CVE-2020-26063
Published: November 5, 2020
Vulnerability identifier: #VU48158
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-26063
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper authorization checks on API endpoints. A remote authenticated attacker can send malicious requests to an API endpoint and download files or modify limited configuration options on the affected system.
Affected software
Cisco Integrated Management Controller
How to mitigate CVE-2020-26063
Install updates from vendor's website.
Cisco Integrated Management Controller - addressed in versions 4.1.2b IMC, 4.1.2b UCSM