CVE-2024-20365
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 77
Summary
CVE-2024-20365 is a newly disclosed vulnerability affecting the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers. An authenticated, remote attacker with administrative privileges can leverage this vulnerability for command injection attacks. The flaw stems from insufficient input validation, enabling an attacker to send maliciously crafted commands through the Redfish API. A successful exploit could result in privilege escalation to the root level.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Unified Computing System
Affected Vendors
- Cisco