Integrated Management Controller
Vendor:
First CVE: Sep 10, 2014 · Active for 11 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Integrated Management Controller over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 10, 2014
11 years ago
Most Recent CVE
May 6, 2021
1,905 days ago
CVE Severity & Scoring
Integrated Management Controller12 CVEs
67%
17%
17%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (25.0%)
Network8 (66.7%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High0 (0.0%)
Unknown1 (8.3%)
User Interaction
None9 (75.0%)
Unknown1 (8.3%)
Required2 (16.7%)
Privileges Required
Low5 (41.7%)
High1 (8.3%)
None5 (41.7%)
Unknown1 (8.3%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15447CRITICAL A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL querie | Nov 8, 2018 | 9.8 | 30 | NO | NO |
CVE-2020-3371HIGH A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands | Nov 6, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-3470CRITICAL Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root pr | Nov 18, 2020 | 9.8 | 25 | NO | NO |
CVE-2019-1632HIGH A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request | Jun 20, 2019 | 8.0 | 24 | NO | NO |
CVE-2019-1879MEDIUM A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands that are executed with root pri | Jun 20, 2019 | 6.7 | 22 | NO | NO |
CVE-2019-1627MEDIUM A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user | Jun 20, 2019 | 6.5 | 22 | NO | NO |
CVE-2021-1397MEDIUM A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to | May 6, 2021 | 6.1 | 20 | NO | NO |
CVE-2019-1630MEDIUM A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, | Jun 20, 2019 | 5.5 | 20 | NO | NO |
CVE-2019-1628MEDIUM A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of | Jun 20, 2019 | 5.5 | 20 | NO | NO |
CVE-2019-1631MEDIUM A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitiv | Jun 20, 2019 | 5.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Integrated Management Controller
Top CWEs
Versions
No cataloged versions.