Impact
The vulnerability stems from improper validation of user supplied arguments in the Cisco Integrated Management Controller web interface. An authenticated attacker with low privileges can craft input that is passed to the underlying operating system, allowing execution of arbitrary commands with root privileges. This creates a critical security gap where a compromised management session leads to full system control.
Affected Systems
Cisco Unified Computing System (Standalone) devices using the affected web‑based IMC software are impacted. The specific product and version information are not listed, so all firmware iterations that have not applied the latest Cisco patch should be treated as vulnerable.
Risk and Exploitability
With a CVSS score of 8.8, the bug is classified as high severity. The EPSS score is unavailable, but the lack of listing in the CISA KEV catalog suggests no known public exploitation yet. Attackers must first authenticate with a low‑privileged account, yet the flaw grants them a straight path to root, making the scenario highly dangerous for exposed management interfaces.
OpenCVE Enrichment