
[CIVN-2026-0402] Multiple Vulnerabilities in Cisco Integrated Management Controller
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Cisco Integrated Management Controller
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Systems Affected
5000 Series Enterprise Network Compute Systems (ENCS)
Catalyst 8300 Series Edge uCPE
UCS C-Series M5 and M6 Rack Servers in standalone mode
UCS C-Series M7 and M8 Rack Servers in standalone mode
UCS E-Series Servers M3
UCS E-Series Servers M6
UCS S-Series Storage Servers in standalone mode
Overview
Multiple vulnerabilities exist in the Cisco Integrated Management Controller (IMC) which could allow an authenticated remote attacker to execute arbitrary commands on the affected system.
Target Audience:
All organizations and individuals using and maintaining CISCO products.
Risk Assessment:
High risk of arbitrary code execution on the underlying operating system.
Impact Assessment:
High impact on Confidentiality, Integrity and Availability of the system.
Description
Cisco Integrated Management Controller (IMC) is an embedded remote management controller for Cisco UCS servers, providing out-of-band administration and hardware management.
Multiple vulnerabilities exist in the web-based management interface of Cisco Integrated Management Controller due to improper validation of user-supplied input. An authenticated remote attacker could exploit these vulnerabilities by submitting crafted inputs to the web-based management interface of the affected software.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.
Solution
Apply appropriate security updates as mentioned by the vendor:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU
References
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU
CVE Name
CVE-2026-20288
CVE-2026-20200
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7J54ACgkQ3jCgcSdc
ys8ySA/+J9ZOkmTCKoOxpJWADSRSQOsJDUmGKK3gLvOJExyrRAu+gLySKF9Jm8Kp
sJGEOns85N63MF/MuUOfeut24pvEW3L1P49pD2U4uRkQWw1uEsYbn6s1CbzfnVnW
E+qxnSqcyoO13a3YrHAT960BiwhuU3IFIsa2bE4ts2Q92w6FM5zTsXZ8pGnQHekh
0b/7QHOu3C7LHgSs/740CCfdseMBUk8iuRAsDULmrh66Tuu6OzChZxRyWfVx6y32
mBZdjnLt/NFBhJAdJhyQUPalHMzBlr1Ac18REbCkHXkswzBVv2WkfW4lXLJsWoEw
pnqC6A73C8sIgKQELBn551IvphlH4p6IolJhnI46uNAJ2XfRQaGp4LYPwQvVrsKO
e+bykKBZ4g7lLMd/0CINb77xJjWik9718z4mpwux8aIwxAXuCAoQPTElgumskRUt
Zt/i/oadkmzWvkoy37ZQdecnFWi+egM2XpO4UyWb59nBFkP4o+aFeoPiyXCMioKB
zTXmgiAj0glEUReTdEh+YMZ61WbcQOnRRpj6brPGVkRIx5Yw8a3xx7f/5lJT4k86
sY0QAaiH+9dJ5ZyHRQU0KFVnAuyGFQkQP8cbh9Ncrw0l89pbqz8LVsS3fJgJXRUI
50uOlJHEtc7f0ZixawGcnG9BXuRyDvnFv8DTQ6JkkJ/eIuHsTYM=
=vCwR
—–END PGP SIGNATURE—–


