HomeSecurityCisco discloses root escalation flaw in IMC

Cisco discloses root escalation flaw in IMC

Cisco has released patches for a high-severity flaw in the Integrated Management Controller (IMC) with public exploit code that could allow root escalation to local attackers.

See also: Intel and Lenovo servers affected by 6-year-old BMC flaw

root escalation defect

Cisco IMC is a base management controller for managing UCS C-Series Rack and UCS S-Series Storage servers through multiple interfaces, including XML API, web (WebUI) , and command line (CLI) interfaces

“ A flaw in the Cisco Integrated Management Controller (IMC) CLI could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system, as well as root escalation ,” the company explains

Known as CVE-2024-20295 , this security flaw is caused by insufficient validation of user -supplied inputs , a weakness that can be exploited using crafted CLI commands as part of low-sophistication attacks.

The vulnerability affects the following Cisco devices running vulnerable IMC versions in default configurations:

  • 5000 Series Enterprise Network Compute Systems (ENCS)
  • Catalyst 8300 Series Edge uCPE
  • UCS C-Series Rack Servers in standalone mode
  • UCS E-Series Servers

See also: CISA: warns of active "Roundcube" email attacks

Cisco

However, it also exposes a long list of other products to attacksif they are configured to provide access to the vulnerable Cisco IMC CLI.

Cisco's Product Security Incident Response Team (PSIRT) also warned in today's advisory that proof-of-concept exploit code is already available, but fortunately, malicious actors have not yet begun targeting the root escalation flaw in attacks.

In October, the company released security patches for two zero-days, which were used to compromise more than 50,000 iOS XE devices within a week.

Attackers also exploited a second zero-day in IOS and IOS XE last year, allowing them to hijack vulnerable devices via remote code execution.

See also: ShadowRay attack targets Ray framework

A root escalation flaw refers to a vulnerability in operating systems that allows a user to gain root or administrator. This means that the user is able to perform actions that are normally restricted to only the system administrator. This type of vulnerability can cause serious security problems, as malicious users can exploit the vulnerability to gain complete access to the system. This can lead to data loss or theft, as well as other forms of malicious activity. To address a root escalation flaw, system administrators must implement appropriate security procedures. This can include updating software to the latest version, enforcing restrictions on user privileges, and monitoring system activity for any suspicious behavior.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS