CRITICAL · 9.8

CVE-2020-3470

Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulner...

Vulnerability Description

Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoEnterprise Nfv Infrastructure Software< 4.4.1
CiscoEnterprise Network Compute System 5100-
CiscoEnterprise Network Compute System 5400-
CiscoIntegrated Management Controller>= 4.0\(1a\), <= 4.0\(4l\)
CiscoC125 M5-
CiscoC220 M5-
CiscoC240 M5-
CiscoC480 M5-
CiscoC480 Ml M5-
CiscoUcs C220 M4-
CiscoUcs C460 M4-
CiscoUcs C22 M3-
CiscoUcs C220 M3-
CiscoUcs C24 M3-
CiscoUcs C240 M3-
CiscoUcs C420 M3-
CiscoUcs E-Series M1-
CiscoUcs E-Series M2-
CiscoUcs E-Series M3-
CiscoUcs S3260-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-3470?

CVE-2020-3470 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulner...

How severe is CVE-2020-3470?

CVE-2020-3470 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-3470?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Enterprise Nfv Infrastructure Software, Cisco Enterprise Network Compute System 5100, Cisco Enterprise Network Compute System 5400, Cisco Integrated Management Controller, Cisco C125 M5.