Cisco Integrated Management Controller(IMC)是美国思科(Cisco)公司的一套用于对UCS(统一计算系统)进行管理的软件。该软件支持HTTP、SSH访问等,并可对服务器进行开机、关机和重启等操作。 Cisco Integrated Management Controller存在输入验证错误漏洞,该漏洞源于vKVM端点验证不足,可能导致重定向攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Unified Computing System (Managed) | 4.0(1a) | - |
|
| Cisco | Cisco Unified Computing System (Standalone) | 2.0(1a) | - |
|
| Cisco | Cisco Unified Computing System E-Series Software (UCSE) | 3.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-20241 | 7.4 HIGH | Cisco Nexus 3000 and 9000 Series Switches IS-IS Protocol <TBD> Denial of Service Vulnerabi |
| CVE-2025-20294 | 6.5 MEDIUM | Cisco UCS Manager Software Command Injection Vulnerability |
| CVE-2025-20344 | 6.5 MEDIUM | Cisco Nexus Dashboard Path Traversal Vulnerability |
| CVE-2025-20295 | 6.0 MEDIUM | Cisco UCS Manager Software Command Injection Vulnerability |
| CVE-2025-20290 | 5.5 MEDIUM | Cisco NXOS Software Sensitive Log Information Disclosure Vulnerability |
| CVE-2025-20342 | 5.4 MEDIUM | Cisco Integrated Management Controller Virtual Keyboard Video Monitor (vKVM) Stored Cross- |
| CVE-2025-20347 | 5.4 MEDIUM | Cisco Nexus Dashboard Fabric Controller Unauthorized REST API Vulnerability |
| CVE-2025-20262 | 5.0 MEDIUM | Cisco Nexus 3000 and 9000 Series Switches Protocol Independent Multicast Version 6 Denial |
| CVE-2025-20348 | 5.0 MEDIUM | Cisco Nexus Dashboard Unauthorized REST API Vulnerability |
| CVE-2025-20292 | 4.4 MEDIUM | Cisco NXOS Software Command Injection Vulnerability |
| CVE-2025-20296 | Cisco UCS Manager Software Stored Software Stored Cross-Site Scripting Vulnerability |
No comments yet