Cisco Integrated Management Controller CLI Command Injection (cisco-sa-cimc-cmd-inj-mUx4c5AJ)

high Nessus Plugin ID 193586

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco Integrated Management Controller CLI is affected by a command injection vulnerability. Due to insufficient validation of user-supplied input, the vulnerability could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have read-only or higher privileges on an affected device.

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwi10842, CSCwi12864, CSCwi29799

See Also

http://www.nessus.org/u?b2ac5fad

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi10842

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi12864

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi29799

Plugin Details

Severity: High

ID: 193586

File Name: cisco-sa-cimc-cmd-inj-mUx4c5AJ.nasl

Version: 1.2

Type: combined

Family: CISCO

Published: 4/19/2024

Updated: 5/15/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.3

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-20295

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cisco:integrated_management_controller

Required KB Items: Host/Cisco/CIMC/version, Host/Cisco/CIMC/model

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/17/2024

Vulnerability Publication Date: 4/17/2024

Reference Information

CVE: CVE-2024-20295

CWE: 78

CISCO-SA: cisco-sa-cimc-cmd-inj-mUx4c5AJ

IAVA: 2024-A-0250

CISCO-BUG-ID: CSCwi10842, CSCwi12864, CSCwi29799