Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise

A serious security vulnerability in the Integrated Management Controller (IMC) that, if properly exploited, may enable an unauthenticated, remote attacker to get around authentication and access the system with elevated rights has been fixed by Cisco with updates.

The vulnerability has a CVSS score of 9.8 out of a possible 10.0, and it is tagged as CVE-2026-20093.

According to a Cisco advisory published on Wednesday, this vulnerability results from improper handling of password update requests. By sending a malicious HTTP request to a compromised device, an attacker could take advantage of this vulnerability.

If the exploit is effective, the attacker may be able to get around authentication, change any user’s password—including that of an administrator—and access the system as that user.

The vulnerability was found and reported by security researcher “jyh” read more about Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *