peter bassill · operator
$ cve CVE-2020-3470 JSON

CVE-2020-3470

9.8
CRITICAL · CVSS 3.1 · EPSS 4.8% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.8% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2020-11-18
Last modified2026-06-17

Affected (21)

VendorProduct
ciscoc125 m5
ciscoc220 m5
ciscoc240 m5
ciscoc480 m5
ciscoc480 ml m5
ciscoenterprise network compute system 5100
ciscoenterprise network compute system 5400
ciscoenterprise nfv infrastructure software
ciscointegrated management controller
ciscoucs c22 m3
ciscoucs c220 m3
ciscoucs c220 m4
ciscoucs c24 m3
ciscoucs c240 m3
ciscoucs c420 m3
ciscoucs c460 m4
ciscoucs e-series m1
ciscoucs e-series m2
ciscoucs e-series m3
ciscoucs s3160
ciscoucs s3260

References

→ the Explorer  ·  watch your stack  ·  NVD