CVE-2020-3243

CRITICAL

Cisco UCS Director - Auth Bypass/Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-3243. PoCs published by mr_me, wvu, including Metasploit module exploits/linux/http/cisco_ucs_cloupia_script_rce.

AI-analyzed exploit summary This Metasploit module exploits an authentication bypass (CVE-2020-3243) and directory traversal (CVE-2020-3250) in Cisco UCS Director to leak an API key and execute arbitrary commands as root via the Cloupia script interpreter.

Description

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Exploits (1)

metasploit WORKING POC EXCELLENT
by mr_me, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/cisco_ucs_cloupia_script_rce.rb

This Metasploit module exploits an authentication bypass (CVE-2020-3243) and directory traversal (CVE-2020-3250) in Cisco UCS Director to leak an API key and execute arbitrary commands as root via the Cloupia script interpreter.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cisco UCS Director < 6.7.4.0
No auth needed
Prerequisites: Network access to the target · SSL/TLS enabled on port 443
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.8837
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-269 CWE-20
Status published
Products (19)
cisco/ucs_director 6.0.0.0
cisco/ucs_director 6.0.0.1
cisco/ucs_director 6.0.1.0
cisco/ucs_director 6.0.1.1
cisco/ucs_director 6.0.1.2
cisco/ucs_director 6.0.1.3
cisco/ucs_director 6.5.0.0
cisco/ucs_director 6.5.0.1
cisco/ucs_director 6.5.0.2
cisco/ucs_director 6.5.0.3
... and 9 more
Published Apr 15, 2020
Tracked Since Feb 18, 2026