logo

Cisco discloses root escalation flaw with public exploit code

ID: b5bdbb6b-b628-5758-af30-8c5838392fd1

STIX ID: report--b5bdbb6b-b628-5758-af30-8c5838392fd1

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2024-04-17

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco disclosed a high-severity CLI command-injection vulnerability (CVE-2024-20295) in its Integrated Management Controller (IMC) affecting multiple product lines (ENCS 5000, Catalyst 8300 uCPE, UCS C-Series standalone, UCS E-Series) that can allow an authenticated local attacker with read-only or greater access to execute crafted commands and gain root; proof-of-concept exploit code is publicly available and Cisco has issued patches, with no confirmed widespread exploitation reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.