peter bassill · operator
$ cve CVE-2020-3248 JSON

CVE-2020-3248

9.8
CRITICAL · CVSS 3.1 · EPSS 74.4% (pctl 99)

Patch early

EPSS 74.4% — above the 10% action threshold.

Description

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS74.44% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2020-04-15
Last modified2026-06-17

Affected (2)

VendorProduct
ciscoucs director
ciscoucs director express for big data

References

→ the Explorer  ·  watch your stack  ·  NVD