CVE-2020-8010

CRITICAL

CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow

Title source: metasploit

Description

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.

Exploits (1)

metasploit WORKING POC EXCELLENT
by wetw0rk · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/nimsoft/nimcontroller_bof.rb

Scores

CVSS v3 9.8
EPSS 0.8094
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
broadcom/unified_infrastructure_management 20.1
broadcom/unified_infrastructure_management < 9.20
Published Feb 18, 2020
Tracked Since Feb 18, 2026