#VU48158 Improper Privilege Management in Cisco Integrated Management Controller - CVE-2020-26063 

 

#VU48158 Improper Privilege Management in Cisco Integrated Management Controller - CVE-2020-26063

Published: November 5, 2020


Vulnerability identifier: #VU48158
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-26063
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Integrated Management Controller
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper authorization checks on API endpoints. A remote authenticated attacker can send malicious requests to an API endpoint and download files or modify limited configuration options on the affected system.


Remediation

Install updates from vendor's website.

External links