Cisco Integrated Management Controller vulnerabilities

4 known vulnerabilities affecting cisco/integrated_management_controller.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2021-1397MEDIUMCVSS 6.1fixed in 3.2\(12.4\)2021-05-06
CVE-2021-1397 [MEDIUM] CWE-601 CVE-2021-1397: A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could exploit this vulnerability by persuadin
nvd
CVE-2020-3470CRITICALCVSS 9.8≥ 4.0\(1a\), ≤ 4.0\(4l\)≥ 3.0\(1c\), ≤ 3.0\(4q\)+4 more2020-11-18
CVE-2020-3470 [CRITICAL] CWE-119 CVE-2020-3470: Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP
nvd
CVE-2020-3371HIGHCVSS 8.8fixed in 3.0\(3e\)2020-11-06
CVE-2020-3371 [MEDIUM] CWE-78 CVE-2020-3371: A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authent A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted commands
nvd
CVE-2014-3348MEDIUMCVSS 5.0≤ 2.2.22014-09-10
CVE-2014-3348 [MEDIUM] CWE-20 CVE-2014-3348: The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers to cause a denial of service (IMC hang) via a crafted SSH packet, aka Bug ID CSCuo69206.
nvd