CVE-2020-3470
9.8
CRITICAL · CVSS 3.1 · EPSS 4.8% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.8% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-11-18 |
| Last modified | 2026-06-17 |
Affected (21)
| Vendor | Product |
|---|---|
| cisco | c125 m5 |
| cisco | c220 m5 |
| cisco | c240 m5 |
| cisco | c480 m5 |
| cisco | c480 ml m5 |
| cisco | enterprise network compute system 5100 |
| cisco | enterprise network compute system 5400 |
| cisco | enterprise nfv infrastructure software |
| cisco | integrated management controller |
| cisco | ucs c22 m3 |
| cisco | ucs c220 m3 |
| cisco | ucs c220 m4 |
| cisco | ucs c24 m3 |
| cisco | ucs c240 m3 |
| cisco | ucs c420 m3 |
| cisco | ucs c460 m4 |
| cisco | ucs e-series m1 |
| cisco | ucs e-series m2 |
| cisco | ucs e-series m3 |
| cisco | ucs s3160 |
| cisco | ucs s3260 |
References
→ the Explorer · watch your stack · NVD