QID 317004

Date Published: 2022-07-05

QID 317004: Cisco Integrated Management Controller Open Redirect Vulnerability (cisco-sa-imc-openred-zAYrU6d2)

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software
could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.

Affected Products
Following Cisco products and software releases:
5000 Series Enterprise Network Compute System (ENCS) releases 4.4.2 and earlier

QID Detection Logic (Authenticated):
The check matches Cisco cimc version retrieved using "show cimc detail " command.

A successful exploit could allow the attacker to redirect a user to a malicious website.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-imc-openred-zAYrU6d2 for more information.

    CVEs related to QID 317004

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-imc-openred-zAYrU6d2 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-imc-openred-zAYrU6d2