Skip to main content

Cisco Releases Advisories for Command Injection Vulnerabilities in Multiple Products

Two vulnerabilities found in devices using Cisco Integrated Management Controller (IMC) could lead to privilege escalation

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Two vulnerabilities found in devices using Cisco Integrated Management Controller (IMC) could lead to privilege escalation


Affected platforms

The following platforms are known to be affected:

Cisco Integrated Management Controller (IMC)

Affects devices running a vulnerable release of Cisco IMC in the default configuration:

  • 5000 Series Enterprise Network Compute Systems (ENCS)
  • Catalyst 8300 Series Edge uCPE
  • UCS C-Series  in standalone mode
  • UCS E-Series Servers
  • UCS S-Series Storage Servers in standalone mode

Also affects devices on a pre-configured version of a Cisco UCS C-Series Server are also affected if they expose access to the Cisco IMC CLI:

  • 5520 and 8540 Wireless Controllers
  • Application Policy Infrastructure Controller (APIC) Servers
  • Business Edition 6000 and 7000 Appliances
  • Catalyst Center Appliances, formerly DNA Center (DNAC)
  • Cloud Services Platform (CSP) 5000 Series
  • Common Services Platform Collector (CSPC) Appliances
  • Connected Mobile Experiences (CMX) Appliances
  • Connected Safety and Security UCS Platform Series Servers
  • Cyber Vision Center Appliances
  • Expressway Series Appliances
  • HyperFlex Edge Nodes
  • HyperFlex Nodes in HyperFlex Datacenter without Fabric Interconnect (DC-NO-FI) deployment mode
  • IEC6400 Edge Compute Appliances
  • IOS XRv 9000 Appliances
  • Meeting Server 1000 Appliances
  • Nexus Dashboard Appliances
  • Prime Infrastructure Appliances
  • Prime Network Registrar Jumpstart Appliances
  • Secure Email Gateways
  • Secure Email and Web Manager
  • Secure Endpoint Private Cloud Appliances
  • Secure Firewall Management Center Appliances, formerly Firepower Management Center
  • Secure Malware Analytics Appliances
  • Secure Network Analytics Appliances
  • Secure Network Server Appliances
  • Secure Web Appliances
  • Secure Workload Servers
  • Telemetry Broker Appliances

Threat details

Introduction

Cisco has released security advisories to address two command injection vulnerabilities in the Command Line Interface (CLI) of the Cisco Integrated Management Controller (IMC), both of which could lead to privilege escalation.

The IMC is a baseboard management controller that provides embedded server management for Cisco UCS C-Series Rack Servers and Cisco UCS S-Series Storage Servers, enabling system management in the data centre and across distributed branch-office locations.


Vulnerability details

  • CVE-2024-20295 is a CLI command injection vulnerability with a CVSSv3 score of 8.8 - an authenticated, local attacker could perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have read-only or higher privileges on an affected device.
  • CVE-2024-20356 is a web-based management interface command injection vulnerability with a CVSS score of 8.7 - an authenticated, remote attacker with Administrator-level privileges could perform command injection attacks on an affected system and elevate their privileges to root.

Proof-of-concept code available for CVE-2024-20295

Cisco PSIRT is aware that proof-of-concept exploit code is available for CVE-2024-20295 but is not aware of any malicious use.


Remediation advice

Affected organisations are encouraged to review the following two advisories and to apply any necessary security updates.


Remediation steps

Type Step
Patch

Cisco Integrated Management Controller CLI Command Injection Vulnerability | cisco-sa-cimc-cmd-inj-mUx4c5AJ


https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-mUx4c5AJ
Patch

Cisco Integrated Management Controller Web-Based Management Interface Command Injection Vulnerability | cisco-sa-cimc-cmd-inj-bLuPcb


https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-bLuPcb


Last edited: 18 April 2024 4:29 pm