Impact
The vulnerability in the Cisco Integrated Management Controller (IMC) web interface allows an authenticated, low‑privileged user to submit malicious arguments that the system forwards directly to the operating‑system command interpreter. A successful exploit gives the attacker the ability to run arbitrary commands with root privileges, effectively taking full control of the host.
Affected Systems
Affected devices are Cisco Unified Computing System (Standalone) models with IMC firmware versions listed in the CPE data, ranging from 4.3(1.230097) through 6.0(1.250194). All firmware iterations that have not yet received a security update to address the argument injection flaw are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, and the EPSS score of <1% suggests a very low current exploitation probability. Because the flaw requires authentication, an attacker must first obtain a low‑privileged account, but the path to root is straightforward once the vulnerability is leveraged. The vulnerability is not currently in the CISA KEV catalog, indicating no publicly known exploits at this time.
OpenCVE Enrichment