Cisco Integrated Management Controller Authentication Bypass (cisco-sa-cimc-auth-bypass-AgG2BxTn)

critical Nessus Plugin ID 304808

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, the Cisco Integrated Management Controller is affected by an authentication bypass vulnerability.

- A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user. (CVE-2026-20093)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwq55648, CSCwq55659, CSCwq68912

See Also

http://www.nessus.org/u?814bb6aa

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq55648

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq55659

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq68912

Plugin Details

Severity: Critical

ID: 304808

File Name: cisco-sa-cimc-auth-bypass-AgG2BxTn.nasl

Version: 1.1

Type: Combined

Family: CISCO

Published: 4/3/2026

Updated: 4/3/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-20093

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:cisco:integrated_management_controller

Required KB Items: Host/Cisco/CIMC/version, Host/Cisco/CIMC/model

Patch Publication Date: 4/1/2026

Vulnerability Publication Date: 4/1/2026

Reference Information

CVE: CVE-2026-20093

CISCO-SA: cisco-sa-cimc-auth-bypass-AgG2BxTn

IAVA: 2026-A-0293

CISCO-BUG-ID: CSCwq55648, CSCwq55659, CSCwq68912