[Security Vulnerability Alert] Two critical cybersecurity vulnerabilities exist in Cisco's Integrated Management Controller.

 
2026/4/14 ~ 2026/10/14
View Count:41

Forwarded from Taiwan Computer Network Crisis Management and Coordination Center: Cybersecurity Alert TWCERTCC-200-202604-00000004

[Content Description]
Cisco's Integrated Management Controller (IMC) is a server management tool specifically designed for Cisco integrated computing systems, providing remote server monitoring, configuration, and management functions. Recently, Cisco issued a major cybersecurity advisory (CVE-2026-20093, CVSS: 9.8 and CVE-2026-20094, CVSS: 8.8).
CVE-2026-20093 is an authentication bypass vulnerability that could allow an unauthenticated remote attacker to bypass authentication and access the system as an administrator. CVE-2026-20094 exists in IMC's web management interface; this is a command injection vulnerability that allows an authenticated remote attacker to execute arbitrary code or commands on the affected underlying operating system and escalate privileges to root.

[Affected Platforms]
Cisco 5000 Series ENCS versions 4.15 and earlier
Cisco Catalyst 8300 Series Edge uCPE versions 4.16 and earlier
Cisco Catalyst 8300 Series Edge uCPE version 4.18
UCS C-Series M5 Rack Server versions 4.2 and earlier
UCS C-Series M5 Rack Server version 4.3
UCS C-Series M6 Rack Server versions 4.2 and earlier
UCS C-Series M6 Rack Server version 4.3
UCS C-Series M6 Rack Server version 6.0
UCS E-Series M3 versions 3.2 and earlier
UCS E-Series M6 version 4.15 (Including) versions prior to this

[Recommended Action]
Patch according to the solutions released on the official website.
【CVE-2026-20093】 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn

【CVE-2026-20094】 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt

[References]
1. https://www.twcert.org.tw/tw/cp-169-10823-4db55-1.html

Files
system_update_alt參考資料
Top↑