Cisco discloses root escalation flaw with public exploit code
ID: b5bdbb6b-b628-5758-af30-8c5838392fd1
STIX ID: report--b5bdbb6b-b628-5758-af30-8c5838392fd1
Feed Name: Bleeping Computer
Cisco disclosed a high-severity CLI command-injection vulnerability (CVE-2024-20295) in its Integrated Management Controller (IMC) affecting multiple product lines (ENCS 5000, Catalyst 8300 uCPE, UCS C-Series standalone, UCS E-Series) that can allow an authenticated local attacker with read-only or greater access to execute crafted commands and gain root; proof-of-concept exploit code is publicly available and Cisco has issued patches, with no confirmed widespread exploitation reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
