CyberWatch

Exploit Code Available for Cisco IMC Vulnerability

By

Matthew Fagan and Alexander Marshall, Access Point Consulting

By

Access Point Consulting

Summary

A vulnerability, classified as CVE-2024-20295 (CVSSv3: 8.8) is present in the CLI of the Cisco Integrated Management Controller (IMC) which could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have read-only or higher privileges on an affected device. The Cisco PSIRT is aware of proof-of-concept exploit code that is available for the vulnerability, however they are not aware of any malicious use of it yet.

Impact Assessment

A successful exploitation of this vulnerability allows a local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. If exploited, this vulnerability would have a high impact because the attacker would have access to root privileges, which are the highest level of access a user can have. Root users can perform security and administrative functions.

Affected Products:

This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco IMC in the default configuration:

  • 5000 Series Enterprise Network Compute Systems (ENCS)
  • Catalyst 8300 Series Edge uCPE
  • UCS C-Series Rack Servers in standalone mode
  • UCS E-Series Servers

Cisco appliances that are based on a preconfigured version of a Cisco UCS C-Series Server are also affected if they expose access to the Cisco IMC CLI. Cisco IMC is not directly accessible on these appliances, which significantly reduces the attack vector on these platforms.

At the time of publication, this included the following Cisco products:

  • 5520 and 8540 Wireless Controllers
  • Application Policy Infrastructure Controller (APIC) Servers
  • Business Edition 6000 and 7000 Appliances
  • Catalyst Center Appliances, formerly DNA Center (DNAC)
  • Cloud Services Platform (CSP) 5000 Series
  • Common Services Platform Collector (CSPC) Appliances
  • Connected Mobile Experiences (CMX) Appliances
  • Connected Safety and Security UCS Platform Series Servers
  • Cyber Vision Center Appliances
  • Expressway Series Appliances
  • HyperFlex Edge Nodes
  • HyperFlex Nodes in HyperFlex Datacenter without Fabric Interconnect (DC-NO-FI) deployment mode
  • IEC6400 Edge Compute Appliances
  • IOS XRv 9000 Appliances
  • Meeting Server 1000 Appliances
  • Nexus Dashboard Appliances
  • Prime Infrastructure Appliances
  • Prime Network Registrar Jumpstart Appliances
  • Secure Email Gateways1
  • Secure Email and Web Manager1
  • Secure Endpoint Private Cloud Appliances
  • Secure Firewall Management Center Appliances, formerly Firepower Management Center
  • Secure Malware Analytics Appliances
  • Secure Network Analytics Appliances
  • Secure Network Server Appliances
  • Secure Web Appliances 1
  • Secure Workload Servers
  • Telemetry Broker Appliances

Products Confirmed Not Vulnerable

Only products listed in the Vulnerable Products section of this advisory are affected by this vulnerability.

Cisco has confirmed that this vulnerability does not affect the following Cisco products:

  • UCS B-Series Blade Servers
  • UCS C-Series Rack Servers managed by Cisco UCS Manager
  • UCS S-Series Storage Servers
  • UCS X-Series Modular Systems

Remediation

For information about which Cisco software releases are vulnerable, see the Fixed Software section of the advisory. Details on updates for the affected products are there as well.

What It Means for You

If you utilize this software or any of the affected products in your environment consult the advisory and apply updates where applicable. This may have to be coordinated with an engineering team, as the upgrade is to a server-related software/device.

Business Implications

As a result of exploitation, an attack can obtain access to root privileges in the command line interface of the Cisco Integrated Management Controller. This can allow the attacker to manage all aspects of the servers within the IMC’s Control. They could modify security settings, utilize SSH, and set a denial-of-service condition on the devices. This can cause monetary and data loss because of incident response and lack of access to the data or applications which live on those servers.

Access Point Consulting Recommends

Patch: Patching the vulnerable device will remediate the vulnerability and prevent exploitation.

Prepare: Make sure the physical security of the local server is up to standard. Due to the attack vector being local, the best way to mitigate this vulnerability is to ensure an attacker cannot reach that server.  

Associated Bulletins

Cisco Integrated Management Controller CLI Command Injection Vulnerability

https://www.cisco.com/c/en/us/products/collateral/servers-unified-computing/ucs-b-series-blade-servers/data_sheet_c78-728802.html

Resources

Latest Resources

Resources

CyberWatch

April 2, 2025

Scott "Monty" Montgomery (Island) | Navigating CMMC compliance for organizations of every size

Scott Montgomery, known as Monty, joined the CyberWatch Expert Series podcast to discuss his extensive background in cybersecurity, particularly in building and designing network security tools for high-assurance environments like the Department of Defense (DoD) and the intelligence community. His experience includes significant tenure at McAfee (now Trellix), which led him to his current role at Island, where he focuses on innovative approaches to cybersecurity compliance.

Find out more
March 19, 2025

Michael Sviben (DomainGuard) | Defending against phishing and building proactive security awareness

Cybersecurity threats evolve rapidly, and one tactic consistently rises above the rest: phishing. In this episode of CyberWatch, Michael Sviben, co-founder of DomainGuard, discusses why phishing remains so effective, how businesses and individuals become targets, and what you can do to stay vigilant.

Find out more
March 5, 2025

David Habib (Brightspot) | Building a culture of cybersecurity awareness

Cybersecurity awareness is often reduced to check-the-box training, but David Habib, CIO at Brightspot, argues that real security awareness isn’t about formal programs—it’s about making security part of a company’s culture. In this episode, he shares practical insights on how organizations can move beyond stale training sessions to create an engaged and security-conscious workforce.

Find out more