Cisco Vulnerabilities: Critical Flaws Allow Admin Access & Remote Control

by Anika Shah - Technology
0 comments

Critical Cisco IMC Flaw Enables Remote Admin Access – Urgent Patching Required

Cisco has issued an urgent security advisory detailing a critical authentication bypass vulnerability in its Integrated Management Controller (IMC) software. The vulnerability, tracked as CVE-2026-20093, allows an unauthenticated, remote attacker to gain full administrative access to affected systems. Immediate patching is advised for organizations utilizing vulnerable Cisco products.

Understanding the Vulnerability

The vulnerability stems from an incorrect handling of password change requests within the IMC. According to Cisco’s advisory, an attacker can exploit this flaw by sending a crafted HTTP request to a vulnerable device, bypassing authentication controls. A successful exploit allows the attacker to alter passwords, including those of administrator accounts, and gain complete control of the system.

Affected Products

The vulnerability impacts a range of Cisco products, including:

  • 5000 Series Enterprise Network Compute Systems (ENCS) – Fixed in 4.15.5
  • Catalyst 8300 Series Edge uCPE – Fixed in 4.18.3
  • UCS C-Series M5 and M6 Rack Servers (standalone mode) – Fixed in 4.3(2.260007), 4.3(6.260017), and 6.0(1.250174)
  • UCS E-Series Servers M3 – Fixed in 3.2.17
  • UCS E-Series Servers M6 – Fixed in 4.15.3

These fixes are available regardless of device configuration, as noted in The Hacker News.

Severity and Impact

The vulnerability carries a Critical CVSS score of 9.8 out of 10, indicating a severe risk. Infosec Bulletin highlights the potential for remote attackers to bypass authentication and gain elevated privileges. This could lead to complete system compromise, data breaches, and disruption of critical services.

Severity and Impact

Additional Vulnerability: Smart Software Manager (SSM)

Cisco also addressed a separate critical vulnerability (CVE-2026-20160) in Smart Software Manager On-Prem (SSM On-Prem). This flaw allows an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to an unintentional exposure of an internal service and can be exploited by sending a crafted request to the API of the exposed service.

Mitigation: Urgent Patching is Essential

Cisco has released software updates to address both vulnerabilities. Organizations are strongly urged to apply these patches immediately to protect their systems. Currently, no workarounds are available, as stated in Cisco’s advisory. Security researcher “jyh” is credited with discovering and reporting the IMC vulnerability.

Key Takeaways

  • A critical authentication bypass vulnerability (CVE-2026-20093) exists in Cisco IMC.
  • Successful exploitation grants attackers full administrative access.
  • Affected products include ENCS, Catalyst 8300, UCS C-Series, and UCS E-Series servers.
  • A separate critical vulnerability (CVE-2026-20160) impacts Smart Software Manager On-Prem.
  • Immediate patching is the recommended mitigation.

Related Posts

Leave a Comment