Cisco Integrated Management Controller Web-Based Management Interface Command Injection (cisco-sa-cimc-cmd-inj-bLuPcb)

high Nessus Plugin ID 197063

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, the Cisco Integrated Management Controller Web-Based Management Interface is affected by a command injection vulnerability. Due to insufficient user input validation, an authenticated, remote attacker with Administrator-level privileges could perform command injection attacks on an affected system and elevate their privileges to root.

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwi42996, CSCwi43001, CSCwi43005, CSCwj41082

See Also

http://www.nessus.org/u?7799f84a

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi42996

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi43001

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi43005

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj41082

Plugin Details

Severity: High

ID: 197063

File Name: cisco-sa-cimc-cmd-inj-bLuPcb.nasl

Version: 1.1

Type: combined

Family: CISCO

Published: 5/15/2024

Updated: 5/16/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.1

CVSS v2

Risk Factor: High

Base Score: 7.7

Temporal Score: 6

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:N

CVSS Score Source: CVE-2024-20356

CVSS v3

Risk Factor: High

Base Score: 8.7

Temporal Score: 7.8

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cisco:integrated_management_controller

Required KB Items: Host/Cisco/CIMC/version, Host/Cisco/CIMC/model

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/17/2024

Vulnerability Publication Date: 4/17/2024

Reference Information

CVE: CVE-2024-20356

CWE: 78

CISCO-SA: cisco-sa-cimc-cmd-inj-bLuPcb

IAVA: 2024-A-0250

CISCO-BUG-ID: CSCwi42996, CSCwi43001, CSCwi43005, CSCwj41082