NA

CVE-2024-20356

Published: 24/04/2024 Updated: 25/04/2024

Vulnerability Summary

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the malicious user to elevate their privileges to root.

Vulnerability Trend

Github Repositories

This is a proof of concept for CVE-2024-20356, a Command Injection vulnerability in Cisco's CIMC.

CVE-2024-20356 This is a proof of concept for CVE-2024-20356, a Command Injection vulnerability in Cisco's CIMC Full technical details can be found at labsnettitudecom/blog/cve-2024-20356-jailbreaking-a-cisco-appliance-to-run-doom Usage Usage: CVE-2024-20356py [-h] -t HOST -u USERNAME -p PASSWORD [-a ACTION] [-c CMD] [-v] options: -h, --help Show t