Cisco Integrated Management Controller(IMC)是美国思科(Cisco)公司的一套用于对UCS(统一计算系统)进行管理的软件。该软件支持HTTP、SSH访问等,并可对服务器进行开机、关机和重启等操作。 Cisco Integrated Management Controller (IMC) 中的 web UI存在操作系统命令注入漏洞,该漏洞允许经过身份验证的远程攻击者在底层操作系统级别注入任意代码并执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Unified Computing System (Standalone) | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-3603 | 7.8 HIGH | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne |
| CVE-2020-3573 | 7.8 HIGH | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne |
| CVE-2020-3593 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3594 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3600 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3604 | 7.8 HIGH | Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulne |
| CVE-2020-3595 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2020-3574 | 7.5 HIGH | Cisco IP Phone TCP Packet Flood Denial of Service Vulnerability |
| CVE-2020-3588 | 7.3 HIGH | Cisco Webex Meetings Desktop App Arbitrary Code Execution Vulnerability |
| CVE-2020-3556 | 7.3 HIGH | Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability |
| CVE-2020-27129 | 6.7 MEDIUM | Cisco SD-WAN vManage Software Command Injection Vulnerability |
| CVE-2020-3592 | 6.5 MEDIUM | Cisco SD-WAN vManage Software Authorization Bypass Vulnerability |
| CVE-2020-26084 | 6.5 MEDIUM | Cisco Edge Fog Fabric Resource Exposure Vulnerability |
| CVE-2020-27128 | 6.5 MEDIUM | Cisco SD-WAN vManage Software Arbitrary File Creation Vulnerability |
| CVE-2020-3590 | 6.4 MEDIUM | Cisco SD-WAN vManage Software Cross-Site Scripting Vulnerability |
| CVE-2020-3587 | 6.4 MEDIUM | Cisco SD-WAN vManage Software Cross-Site Scripting Vulnerability |
| CVE-2020-3551 | 6.1 MEDIUM | Cisco Identity Services Engine Cross-Site Scripting Vulnerability |
| CVE-2020-27123 | 5.5 MEDIUM | Cisco AnyConnect Secure Mobility Client for Windows Arbitrary File Read Vulnerability |
| CVE-2020-26083 | 4.8 MEDIUM | Cisco Identity Services Engine Cross-Site Scripting Vulnerability |
| CVE-2020-27121 | 4.3 MEDIUM | Cisco Unified Communications Manager IM and Presence Service Denial of Service Vulnerabili |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet