Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-20095— Cisco Integrated Management Controller Command Injection Vulnerability

CVSS 6.5 · Medium EPSS 0.09% · P25
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-20095

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Integrated Management Controller Command Injection Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has assigned this vulnerability a Security Impact Rating (SIR) of High, rather than Medium as the score indicates, because additional security implications could occur once the attacker has become root.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco Integrated Management Controller 命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Integrated Management Controller(IMC)是美国思科(Cisco)公司的一套用于对UCS(统一计算系统)进行管理的软件。该软件支持HTTP、SSH访问等,并可对服务器进行开机、关机和重启等操作。 Cisco Integrated Management Controller存在命令注入漏洞,该漏洞源于用户提供输入验证不当,可能导致具有管理员级别权限的已验证远程攻击者进行命令注入攻击并执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

II. Public POCs for CVE-2026-20095

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-20095

登录查看更多情报信息。

Same Patch Batch · Cisco · 2026-04-01 · 16 CVEs total

CVE-2026-201609.8 CRITICALCisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
CVE-2026-200939.8 CRITICALCisco Integrated Management Controller Authentication Bypass Vulnerability
CVE-2026-200948.8 HIGHCisco Integrated Management Controller Command Injection Vulnerability
CVE-2026-201558.0 HIGHCisco Evolved Programmable Network Manager Improper Authorization Vulnerability
CVE-2026-201517.3 HIGHCisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
CVE-2026-200966.5 MEDIUMCisco Integrated Management Controller Command Injection Vulnerability
CVE-2026-200976.5 MEDIUMCisco Integrated Management Controller Remote Code Execution Vulnerability
CVE-2026-200426.5 MEDIUMCisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability
CVE-2026-200856.1 MEDIUMCisco Integrated Management Controller Cross-Site Scripting Vulnerability
CVE-2026-200416.1 MEDIUMCisco Nexus Dashboard Server Side Request Forgery Vulnerability
CVE-2026-201744.9 MEDIUMCisco Nexus Dashboard Insights Arbitrary File Write Vulnerability
CVE-2026-200904.8 MEDIUMCisco Integrated Management Controller Cross-Site Scripting Vulnerability
CVE-2026-200894.8 MEDIUMCisco Integrated Management Controller Cross-Site Scripting Vulnerability
CVE-2026-200874.8 MEDIUMCisco Integrated Management Controller Cross-Site Scripting Vulnerability
CVE-2026-200884.8 MEDIUMCisco Integrated Management Controller Cross-Site Scripting Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2026-20095

No comments yet


Leave a comment