CVE-2024-20365

MEDIUM

Cisco Unified Computing System - Authenticated Command Injection via Redfish API

Title source: llm
STIX 2.1

Description

A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers could allow an authenticated, remote attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root. This vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending crafted commands through the Redfish API on an affected device. A successful exploit could allow the attacker to elevate privileges to root.

Scores

CVSS v3 6.5
EPSS 0.0018
EPSS Percentile 39.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (43)
cisco/unified_computing_system 4.1\(2a\)
cisco/unified_computing_system 4.1\(2b\)
cisco/unified_computing_system 4.1\(2c\)
cisco/unified_computing_system 4.1\(3a\)
cisco/unified_computing_system 4.1\(3b\)
cisco/unified_computing_system 4.1\(3c\)
cisco/unified_computing_system 4.1\(3d\)
cisco/unified_computing_system 4.1\(3e\)
cisco/unified_computing_system 4.1\(3f\)
cisco/unified_computing_system 4.1\(3h\)
... and 33 more
Published Oct 02, 2024
Tracked Since Feb 18, 2026