CVE-2020-3470
published 2020-11-18CVE-2020-3470: Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute…
PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.60%
90.6th percentile
Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system | — | — |
| cisco | enterprise_nfv_infrastructure_software | < 4.4.1 | 4.4.1 |
| cisco | integrated_management_controller | < 3.2.11.3 | 3.2.11.3 |
| cisco | integrated_management_controller | 3.0\(1c\) – 3.0\(4q\) | — |
| cisco | integrated_management_controller | 3.1 – 4.0\(4l\) | — |
| cisco | integrated_management_controller | 4.0\(1a\) – 4.0\(4l\) | — |
| cisco | integrated_management_controller | 4.0\(1a\) – 4.0\(2l\) | — |
| cisco | integrated_management_controller | 4.1\(1c\) – 4.1\(1f\) | — |
| cisco | integrated_management_controller_multiple | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted HTTP requests targeting the Cisco IMC API subsystem that may trigger a buffer overflow condition ↗
- →Focus detection on oversized or malformed user-supplied input fields in HTTP requests to the Cisco IMC API, consistent with improper boundary check exploitation ↗
- ·No workarounds are available for these vulnerabilities; patching via Cisco software updates is the only remediation path ↗
- ·Exploitation is unauthenticated and remote, meaning no credentials are required — network-level access controls to the IMC API are critical compensating controls ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Integrated Management Controller Multiple Remote Code Execution Vulnerabilities
vendor_cisco·2020-11-18·CVSS 9.8
CVE-2020-3470 [CRITICAL] CWE-119 Cisco Integrated Management Controller Multiple Remote Code Execution Vulnerabilities
Cisco Integrated Management Controller Multiple Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges.
The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).
Cisco has released software updates that address these vulnerabilities. There are no work
Cisco
Cisco Integrated Management Controller Multiple Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3470 Cisco Integrated Management Controller Multiple Remote Code Execution Vulnerabilities
CVE-2020-3470: Cisco Integrated Management Controller Multiple Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS). Cisco has released software updates that address these vulnerabilities. Ther
GHSA
GHSA-q622-qgp9-63h7: Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execu
ghsa_unreviewed·2022-05-24
CVE-2020-3470 [CRITICAL] CWE-119 GHSA-q622-qgp9-63h7: Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execu
Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).
Suricata
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1440 [HIGH] ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author UPDATE
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author UPDATE"; flow:established,to_server; http.uri; content:"/search.asp?"; nocase; content:"author="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-1440; reference:url,www.milw0rm.com/exploits/3470; classtype:web-application-attack; sid:2004342; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, m
Suricata
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1440 [HIGH] ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author INSERT
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author INSERT"; flow:established,to_server; http.uri; content:"/search.asp?"; nocase; content:"author="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-1440; reference:url,www.milw0rm.com/exploits/3470; classtype:web-application-attack; sid:2004339; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190,
Suricata
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1440 [HIGH] ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author UNION SELECT
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author UNION SELECT"; flow:established,to_server; http.uri; content:"/search.asp?"; nocase; content:"author="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1440; reference:url,www.milw0rm.com/exploits/3470; classtype:web-application-attack; sid:2004338; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniq
Suricata
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-1440 [HIGH] ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author ASCII
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author ASCII"; flow:established,to_server; http.uri; content:"/search.asp?"; nocase; content:"author="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1440; reference:url,www.milw0rm.com/exploits/3470; classtype:web-application-attack; sid:2004341; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190,
Suricata
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1440 [HIGH] ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author SELECT
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author SELECT"; flow:established,to_server; http.uri; content:"/search.asp?"; nocase; content:"author="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1440; reference:url,www.milw0rm.com/exploits/3470; classtype:web-application-attack; sid:2004337; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190,
Suricata
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1440 [HIGH] ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author DELETE
ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS JGBBS SQL Injection Attempt -- search.asp author DELETE"; flow:established,to_server; http.uri; content:"/search.asp?"; nocase; content:"author="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1440; reference:url,www.milw0rm.com/exploits/3470; classtype:web-application-attack; sid:2004340; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190,
No public exploits indexed.
No writeups or analysis indexed.
2020-11-18
Published