Cisco Integrated Management Controller Command Injection (CVE-2024-20356)

Related Vulnerabilities: CVE-2024-20356  

Check Point Reference: CPAI-2024-0235 Date Published: 12 May 2024 Severity: High Last Updated: Sunday 12 May, 2024 Source: Industry Reference:CVE-2024-20356
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Cisco 5000 Series Enterprise Network Compute Systems (ENCS)
Cisco Catalyst 8300 Series Edge uCPE
Cisco UCS C-Series M5, M6, and M7 Rack Servers
Cisco UCS E-Series Servers
Cisco UCS S-Series Storage Servers Vulnerability Description A command injection vulnerability exists in Cisco integrated management controller. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary commands on the affected system.