Description

A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers could allow an authenticated, remote attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root. This vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending crafted commands through the Redfish API on an affected device. A successful exploit could allow the attacker to elevate privileges to root.

INFO

Published Date :

2024-10-02T16:52:46.381Z

Last Modified :

2024-10-02T20:08:13.029Z

Source :

cisco
AFFECTED PRODUCTS

The following products are affected by CVE-2024-20365 vulnerability.

Vendors Products
Cisco
  • Unified Computing System
  • Unified Computing System Manager Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-20365.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact