Vulnerability Description
Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Enterprise Nfv Infrastructure Software | < 4.4.1 |
| Cisco | Enterprise Network Compute System 5100 | - |
| Cisco | Enterprise Network Compute System 5400 | - |
| Cisco | Integrated Management Controller | >= 4.0\(1a\), <= 4.0\(4l\) |
| Cisco | C125 M5 | - |
| Cisco | C220 M5 | - |
| Cisco | C240 M5 | - |
| Cisco | C480 M5 | - |
| Cisco | C480 Ml M5 | - |
| Cisco | Ucs C220 M4 | - |
| Cisco | Ucs C460 M4 | - |
| Cisco | Ucs C22 M3 | - |
| Cisco | Ucs C220 M3 | - |
| Cisco | Ucs C24 M3 | - |
| Cisco | Ucs C240 M3 | - |
| Cisco | Ucs C420 M3 | - |
| Cisco | Ucs E-Series M1 | - |
| Cisco | Ucs E-Series M2 | - |
| Cisco | Ucs E-Series M3 | - |
| Cisco | Ucs S3260 | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uVendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uVendor Advisory
FAQ
What is CVE-2020-3470?
CVE-2020-3470 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulner...
How severe is CVE-2020-3470?
CVE-2020-3470 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-3470?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Enterprise Nfv Infrastructure Software, Cisco Enterprise Network Compute System 5100, Cisco Enterprise Network Compute System 5400, Cisco Integrated Management Controller, Cisco C125 M5.