Cisco Integrated Management Controller
cpe:2.3:a:cisco:integrated_management_controller:*:*:*:*:*:*:*
- <= 4.2
- <= 3.2
- <= 4.15
An authentication bypass vulnerability has been identified in the password change functionality of Cisco Integrated Management Controller (IMC). This issue allows an unauthenticated, remote attacker to gain access to the system as an Admin user. The vulnerability arises from improper handling of password change requests, enabling attackers to send crafted HTTP requests that bypass authentication and modify passwords for any user, including Admin.
Exploitation of this vulnerability could lead to unauthorized access to the system as an Admin user, allowing the attacker to manipulate user accounts and potentially access sensitive system functions or data.
Cisco has released software updates to address this vulnerability. Instructions for upgrading to the fixed releases are available in the Cisco Security Advisory related to this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.