Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-3243.
PoCs published by mr_me, wvu, including Metasploit module exploits/linux/http/cisco_ucs_cloupia_script_rce.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass (CVE-2020-3243) and directory traversal (CVE-2020-3250) in Cisco UCS Director to leak an API key and execute arbitrary commands as root via the Cloupia script interpreter.
Description
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Exploits (1)
This Metasploit module exploits an authentication bypass (CVE-2020-3243) and directory traversal (CVE-2020-3250) in Cisco UCS Director to leak an API key and execute arbitrary commands as root via the Cloupia script interpreter.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H