peter bassill · operator
$ cve CVE-2020-3250 JSON

CVE-2020-3250

9.8
CRITICAL · CVSS 3.1 · EPSS 60.9% (pctl 99)

Patch early

EPSS 60.9% — above the 10% action threshold.

Description

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS60.95% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2020-04-15
Last modified2026-06-17

Affected (2)

VendorProduct
ciscoucs director
ciscoucs director express for big data

References

→ the Explorer  ·  watch your stack  ·  NVD