HomeUpdatesCisco fixes serious bugs in IMC and SSM

Cisco fixes serious bugs in IMC and SSM

Cisco has released updates to address a critical security flaw in the Integrated Management Controller ( IMC). Successful exploitation of the vulnerability could allow an unauthorized, remote attacker to bypass authentication and gain privileges elevated system .

Cisco IMC

The vulnerability, tracked as CVE-2026-20093, carries a CVSS score of 9.8/10.0.

“This vulnerability is due to improper handling of password change requests,” said in an advisory. “An attacker could exploit this vulnerability by sending a specially crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, change the passwords of any user on the system, including an Admin user, and gain access to the system as that user.”

See also: Claude Code discovered zero-day in Vim and GNU Emacs

Security researcher “jyh” discovered and reported the vulnerability to Cisco. The issue affects the following products regardless of device configuration:

  • 5000 Series Enterprise Network Compute Systems (ENCS) – Patch in 4.15.5
  • Catalyst 8300 Series Edge uCPE – Fix in 4.18.3
  • UCS C-Series M5 and M6 Rack Servers in standalone mode – Fix in 4.3(2.260007), 4.3(6.260017) and 6.0(1.250174)
  • UCS E-Series Servers M3 – Fix in 3.2.17
  • UCS E-Series Servers M6 – Fix in 4.15.3
Cisco fixes serious bugs in IMC and SSM

Cisco: Fixing vulnerability in SSM On-Prem

Another critical vulnerability, patched by Cisco, affects Smart Software Manager On-Prem (SSM On-Prem), which could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability, CVE-2026-20160 (CVSS score: 9.8), results from an inadvertent exposure of an internal service.

See also: TrueConf: Zero-day vulnerability used in attacks on government networks

“An attacker could exploit this vulnerability by sending a crafted request to the exposed service’s API,” Cisco said. “A successful exploit could allow the attacker to execute commands on the underlying operating system with privileges root-level.”

Fixes for the bug have been released in Cisco SSM On-Prem release 9-202601 . Cisco said the vulnerability was discovered internally during the resolution of a Cisco Technical Assistance Center (TAC) support case .

See also: F5 BIG-IP APM: Critical RCE vulnerability used in attacks

Cisco fixes serious bugs in IMC and SSM

While none of the vulnerabilities have been used in actual attacks, users and businesses should be on the lookout and apply security updates. Cybercriminals have exploited many Cisco vulnerabilities in the past. In the absence of an alternative, customers are urged to update their systems to the patched version.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS