CVE-2026-20288

1 karet z 1 položek · v celém archivu · celý přehled CZ · EN/orig

CVE-2026-20288

EPSS 0.00 EPSS k 18. 9. 2026

Hodnocení závažnosti

6.5 CVSS 3.1 cisco

útok odkudkoli z internetu bez přípravy nutná práva správce bez zásahu uživatele
dopad plný únik dat úplná změna dat bez výpadku
přesah dopad jen na zranitelnou součást

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

zvyšuje závažnost mírně zvyšuje závažnost snižuje závažnost

1

Cisco Integrated Management Controller Argument Injection Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities…

EPSS 0.06 CVE-2026-20200 CVE-2026-20288 Cisco US

· Cisco PSIRT · Cisco Integrated Management Controller Argument Injection Vulnerabilities