Tag: Integrated Management Controller (IMC)

Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
News

Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise

A serious security vulnerability in the Integrated Management Controller (IMC) that, if properly exploited, may enable an unauthenticated, remote attacker to get around authentication and access the system with elevated rights has been fixed by Cisco with updates. The vulnerability has a CVSS score of 9.8 out of a possible 10.0, and it is tagged as CVE-2026-20093. According to a Cisco advisory published on Wednesday, this vulnerability results from improper handling of password update requests. By sending a malicious HTTP request to a compromised device, an attacker could take advantage of this vulnerability. If the exploit is effective, the attacker may be able to get around authentication, change any user's password—including that of an administrator—and access the system as th...