nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37070 CVE-2020-37070
HIGH
CloudMe 1.11.2 - Buffer Overflow (SEH,DEP,ASLR)
Record summary
CVE-2020-37070 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.
Description
CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attackers can exploit the vulnerability by sending a specially crafted payload to the CloudMe service running on port 8888, enabling remote code execution.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CloudMeBrowse CloudMe / CloudMe | CVE List | 1.11.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCloudMe 1.11.2 - Buffer Overflow (SEH_DEP_ASLR)ExploitDB exploitby Xenofon VassilakopoulosNot analyzed1 file
References
4CloudMe Official Homepageproduct
https://www.cloudme.com/en ExploitDB-48499exploit
https://www.exploit-db.com/exploits/48499 VulnCheck Advisory: CloudMe 1.11.2 - Buffer Overflow (SEH,DEP,ASLR)Third-party advisory
https://www.vulncheck.com/advisories/cloudme-buffer-overflow-sehdepaslr