Description

A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable system without authorization. The vulnerability is due to improper authorization checks on API endpoints. An attacker could exploit this vulnerability by sending malicious requests to an API endpoint. An exploit could allow the attacker to download files from or modify limited configuration options on the affected system.There are no workarounds that address this vulnerability.

INFO

Published Date :

2024-11-18T16:05:53.165Z

Last Modified :

2024-11-18T19:49:33.809Z

Source :

cisco
AFFECTED PRODUCTS

The following products are affected by CVE-2020-26063 vulnerability.

Vendors Products
Cisco
  • Unified Computing System

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact