CVE-2020-8012

CRITICAL

Broadcom Unified Infrastructure Management < 9.20 - Buffer Overflow

Title source: rule

Description

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

Exploits (3)

exploitdb WORKING POC
by wetw0rk · cremotewindows
https://www.exploit-db.com/exploits/48156
nomisec WORKING POC 75 stars
by wetw0rk · poc
https://github.com/wetw0rk/Exploit-Development
metasploit WORKING POC EXCELLENT
by wetw0rk · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/nimsoft/nimcontroller_bof.rb

Scores

CVSS v3 9.8
EPSS 0.8389
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (2)
broadcom/unified_infrastructure_management 20.1
broadcom/unified_infrastructure_management < 9.20
Published Feb 18, 2020
Tracked Since Feb 18, 2026