cbcvebase.
CVE-2025-20261
published 2025-06-04

CVE-2025-20261: A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS…

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.40%
32.7th percentile
A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges. This vulnerability is due to insufficient restrictions on access to internal services. An attacker with a valid user account could exploit this vulnerability by using crafted syntax when connecting to the Cisco IMC of an affected device through SSH. A successful exploit could allow the attacker to access internal services with elevated privileges, which may allow unauthorized modifications to the system, including the possibility of creating new administrator accounts on the affected device.

Affected

143 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system
ciscocisco_unified_computing_system

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is SSH connection to Cisco IMC using crafted syntax — monitor SSH sessions to IMC management interfaces for anomalous or malformed connection syntax from authenticated users
  • Post-exploitation indicator: watch for unexpected creation of new administrator accounts on Cisco IMC/UCS devices following SSH activity
  • Affected platforms: Cisco UCS B-Series, C-Series, S-Series, and X-Series Servers running Cisco IMC — scope detection and patching to these device families
  • ·No workaround exists; Cisco states only software updates address this vulnerability. A mitigation (not a workaround) is noted as available — review the advisory for mitigation details.
  • ·Vulnerability is exploitable by any authenticated user (not just privileged accounts) — restrict SSH access to Cisco IMC management interfaces to trusted hosts/networks as a mitigation measure
  • ·Tracked under Cisco Bug IDs CSCwc06871 and CSCwk24502 — use these IDs to query Cisco's bug tracker for affected software release ranges and fixed versions

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.