云虫漏洞库

CVE-2026-20097 - A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the un - 漏洞详情

漏洞编号:CVE-2026-20097

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-20097

CNNVD 编号:-

厂商/产品:cisco / unified_computing_system

影响范围:cpe:2.3:a:cisco:unified_computing_system:3.1\(1d\):*:*:*:*:*:*:*

CWE:CWE-787

发布/更新时间:2026-04-01 / 2026-08-28

漏洞描述

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system as the root user.

Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.

相关链接

相关漏洞

« 返回首页