cbcvebase.
CVE-2017-6616
published 2017-04-20

CVE-2017-6616: A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary…

PriorityP261high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
4.24%
90.0th percentile
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize specific values that are received as part of a user-supplied HTTP request. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the user on the affected system. Cisco Bug IDs: CSCvd14578.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscointegrated_management_controller
ciscointegrated_management_controller_supervisor
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-2build0.18.04.12.3.0-2build0.18.04.1

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted HTTP request to the Cisco IMC web-based GUI; monitor for anomalous or malformed HTTP requests targeting the IMC web interface that may carry unsanitized user-supplied values
  • Successful exploitation results in system command execution with root-level privileges from the IMC web GUI process; alert on unexpected privileged process spawning from the IMC web server
  • Track Cisco Bug IDs CSCvd14578, CSCve48833, and CSCvg31284 for patch/signature updates related to this vulnerability
  • ·NVD describes the vulnerability as requiring authentication, while the Cisco advisory describes it as exploitable by an unauthenticated attacker — defenders should treat the attack surface as unauthenticated (no-auth required) for conservative detection and patching posture
  • ·The vulnerability is confirmed in Cisco IMC version 3.0(1c); ensure all IMC firmware versions are assessed against the full list of affected releases in the Cisco advisory
  • ·There are no workarounds available; patching is the only mitigation

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv9.8CRITICAL
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.