CVE-2024-20365

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 77

Summary

CVE-2024-20365 is a newly disclosed vulnerability affecting the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers. An authenticated, remote attacker with administrative privileges can leverage this vulnerability for command injection attacks. The flaw stems from insufficient input validation, enabling an attacker to send maliciously crafted commands through the Redfish API. A successful exploit could result in privilege escalation to the root level.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Unified Computing System

Affected Vendors

  • Cisco