NA

CVE-2024-20356

Published: 24/04/2024 Updated: 25/04/2024

Vulnerability Summary

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the malicious user to elevate their privileges to root.

Vulnerability Trend

Vendor Advisories

Check Point Reference: CPAI-2024-0235 Date Published: 12 May 2024 Severity: High ...

Github Repositories

This is a proof of concept for CVE-2024-20356, a Command Injection vulnerability in Cisco's CIMC.

CVE-2024-20356 This is a proof of concept for CVE-2024-20356, a Command Injection vulnerability in Cisco's CIMC Full technical details can be found at labsnettitudecom/blog/cve-2024-20356-jailbreaking-a-cisco-appliance-to-run-doom Usage Usage: CVE-2024-20356py [-h] -t HOST -u USERNAME -p PASSWORD [-a ACTION] [-c CMD] [-v] options: -h, --help Show t