Cisco Unified Computing System E-Series Software vulnerabilities
23 known vulnerabilities affecting cisco/cisco_unified_computing_system_e-series_software.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH13MEDIUM9
Vulnerabilities
Page 1 of 2
CVE-2026-20093CRITICALCVSS 9.8v3.2.7v3.2.6+40 more2026-04-01
CVE-2026-20093 [CRITICAL] CWE-20 CVE-2026-20093: A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC)
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin.
This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a
cvelistv5nvd
CVE-2026-20094HIGHCVSS 8.8v3.2.7v3.2.6+40 more2026-04-01
CVE-2026-20094 [HIGH] CWE-77 CVE-2026-20094: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vu
cvelistv5nvd
CVE-2026-20085MEDIUMCVSS 6.1v3.2.7v3.2.6+40 more2026-04-01
CVE-2026-20085 [MEDIUM] CWE-79 CVE-2026-20085: A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, r
A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a
cvelistv5nvd
CVE-2026-20096MEDIUMCVSS 6.5v3.2.7v3.2.6+40 more2026-04-01
CVE-2026-20096 [MEDIUM] CWE-77 CVE-2026-20096: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit thi
cvelistv5nvd
CVE-2026-20090MEDIUMCVSS 4.8v3.2.7v3.2.6+40 more2026-04-01
CVE-2026-20090 [MEDIUM] CWE-79 CVE-2026-20090: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
cvelistv5nvd
CVE-2026-20095MEDIUMCVSS 6.5v3.2.7v3.2.6+40 more2026-04-01
CVE-2026-20095 [MEDIUM] CWE-77 CVE-2026-20095: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit thi
cvelistv5nvd
CVE-2026-20087MEDIUMCVSS 4.8v3.2.7v3.2.6+40 more2026-04-01
CVE-2026-20087 [MEDIUM] CWE-79 CVE-2026-20087: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
cvelistv5nvd
CVE-2026-20088MEDIUMCVSS 4.8v3.2.7v3.2.6+34 more2026-04-01
CVE-2026-20088 [MEDIUM] CWE-79 CVE-2026-20088: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
cvelistv5nvd
CVE-2026-20089MEDIUMCVSS 4.8v3.2.7v3.2.6+40 more2026-04-01
CVE-2026-20089 [MEDIUM] CWE-79 CVE-2026-20089: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
cvelistv5nvd
CVE-2025-20317HIGHCVSS 7.1v3.2.7v3.2.6+39 more2025-08-27
CVE-2025-20317 [HIGH] CWE-601 CVE-2025-20317: A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website.
This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading
cvelistv5nvd
CVE-2025-20342MEDIUMCVSS 5.4v3.2.7v3.2.6+39 more2025-08-27
CVE-2025-20342 [MEDIUM] CWE-80 CVE-2025-20342: A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient validation of user-supplied
cvelistv5nvd
CVE-2024-20356HIGHCVSS 8.7v2.1.0v2.4.0+34 more2024-04-24
CVE-2024-20356 [HIGH] CWE-78 CVE-2024-20356: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to insufficient user input validation. An attac
cvelistv5nvd
CVE-2024-20295HIGHCVSS 8.8vN/A2024-04-24
CVE-2024-20295 [HIGH] CWE-78 CVE-2024-20295: A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authen
A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have read-only or higher privileges on an affected device. This vulnerability
cvelistv5nvd
CVE-2023-20228MEDIUMCVSS 6.1v2.1.0v2.4.0+35 more2023-08-16
CVE-2023-20228 [MEDIUM] CWE-80 CVE-2023-20228: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persua
cvelistv5nvd
CVE-2019-1865HIGHCVSS 8.8≥ unspecified, < 2.0(13o)2019-08-21
CVE-2019-1865 [HIGH] CWE-78 CVE-2019-1865: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An atta
cvelistv5nvd
CVE-2019-1634HIGHCVSS 7.2≥ unspecified, < 2.0(13o)2019-08-21
CVE-2019-1634 [HIGH] CWE-78 CVE-2019-1634: A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Manageme
A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on the underlying operating system (OS). The vulnerability is due to insufficient input validation of user-supplied comman
cvelistv5nvd
CVE-2019-1883HIGHCVSS 7.8≥ unspecified, < 3.0(4k)2019-08-21
CVE-2019-1883 [HIGH] CWE-78 CVE-2019-1883: A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input on the command-line interface. An atta
cvelistv5nvd
CVE-2019-1896HIGHCVSS 7.2≥ unspecified, < 3.0(4k)2019-08-21
CVE-2019-1896 [HIGH] CWE-78 CVE-2019-1896: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request (CSR) function of the web-based managemen
cvelistv5nvd
CVE-2019-1863HIGHCVSS 8.1≥ unspecified, < 2.0(13o)2019-08-21
CVE-2019-1863 [HIGH] CWE-285 CVE-2019-1863: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by sending a crafted HTTP r
cvelistv5nvd
CVE-2019-1864HIGHCVSS 8.8≥ unspecified, < 2.0(13o)2019-08-21
CVE-2019-1864 [HIGH] CWE-78 CVE-2019-1864: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of command input by the affected software. An attacker c
cvelistv5nvd
1 / 2Next →