Impact
A flaw in the web‑based management interface of Cisco IMC allows an authenticated attacker with administrative privilege to inject malicious input that is not properly validated. Successful exploitation gives the attacker the ability to run arbitrary commands on the host operating system with root privileges, leading to full compromise of the affected device. The vulnerability is classified as CWE‑146, reflecting the failure to properly encode or validate user input.
Affected Systems
The affected products are Cisco Unified Computing System (Standalone) and Cisco Unified Computing System E‑Series Software (UCSE). No specific version numbers are supplied in the advisory, so all current or older versions of these products should be assessed for the presence of the vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate‑to‑high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that it has not yet been widely observed in the wild. However, the attack requires the attacker to be authenticated with Admin privileges, so the risk is contingent on privileged access. If an attacker gains such access, they can elevate to root and execute arbitrary code on the underlying system. The advisory notes that the SIR is High because of the potential for root-level compromise, so an effective risk is the possibility of a full system takeover by a authenticated adversary.
OpenCVE Enrichment