Cisco IMC Unauthenticated Admin Access via Redfish/API - CVE-2026-20093

This rule detects successful HTTP requests (status 200, 201, 202) directed towards management interfaces (Redfish, CIMC, OSS APIs) by unauthenticated or anonymous users originating from outside the internal network. The rule calculates a risk level based on the variety and frequency of requested paths, flagging potential unauthorized enumeration or exploitation attempts against server infrastructure.