【Security Vulnerability Alert】Cisco Integrated Management Controller contains a critical security vulnerability (CVE-2026-20200)

 
2026/8/10 ~ 2027/2/10
View Count:15

Forwarded Taiwan Computer Network Emergency Response Team/Coordination Center Information Security Alert TWCERTCC-200-202608-00000003

[Content Description]
Cisco Integrated Management Controller (IMC) is a management tool designed for servers in Cisco Unified Computing System, providing remote monitoring, configuration, and management functions for servers. Recently, Cisco released a critical security advisory (CVE-2026-20200, CVSS: 8.8). This vulnerability allows an authenticated remote attacker to execute arbitrary code or commands on the affected underlying operating system and elevate privileges to root.

[Impacted Platform]
UCS C-Series M7 and M8 Rack Servers in standalone mode

[Recommended Actions]
Please perform patching according to the solution released on the official website: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU

[Reference]
1. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU
2. https://nvd.nist.gov/vuln/detail/CVE-2026-20200

Files
system_update_alt參考資料1
system_update_alt參考資料2
Top↑