cbcvebase.
CVE-2020-3470
published 2020-11-18

CVE-2020-3470: Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute…

PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.60%
90.6th percentile
Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).

Affected

9 ranges
VendorProductVersion rangeFixed in
ciscocisco_unified_computing_system
ciscoenterprise_nfv_infrastructure_software< 4.4.14.4.1
ciscointegrated_management_controller< 3.2.11.33.2.11.3
ciscointegrated_management_controller3.0\(1c\) – 3.0\(4q\)
ciscointegrated_management_controller3.1 – 4.0\(4l\)
ciscointegrated_management_controller4.0\(1a\) – 4.0\(4l\)
ciscointegrated_management_controller4.0\(1a\) – 4.0\(2l\)
ciscointegrated_management_controller4.1\(1c\) – 4.1\(1f\)
ciscointegrated_management_controller_multiple

Detection & IOCsextracted from sources · hover to see the quote

  • Detect crafted HTTP requests targeting the Cisco IMC API subsystem that may trigger a buffer overflow condition
  • Focus detection on oversized or malformed user-supplied input fields in HTTP requests to the Cisco IMC API, consistent with improper boundary check exploitation
  • ·No workarounds are available for these vulnerabilities; patching via Cisco software updates is the only remediation path
  • ·Exploitation is unauthenticated and remote, meaning no credentials are required — network-level access controls to the IMC API are critical compensating controls

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.