Vulnerability record · CVE-2020-3239 · published 15 April 2020
CVE-2020-3239: Cisco UCS Director REST API auth bypass and path traversal
Cisco · Ucs Director
The REST API of Cisco UCS Director and UCS Director Express for Big Data contains multiple input validation flaws that let a remote attacker bypass authentication or perform directory traversal. The advisory groups several issues under one CVE and does not detail each individually, so the exact per-endpoint behavior is not fully described.
Description
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (8.8) with very high EPSS and an authentication bypass plus file read, but no KEV listing or documented exploitation.
What it is
The REST API of Cisco UCS Director and UCS Director Express for Big Data contains multiple input validation flaws that let a remote attacker bypass authentication or perform directory traversal. The advisory groups several issues under one CVE and does not detail each individually, so the exact per-endpoint behavior is not fully described.
Impact
An attacker can bypass authentication to reach protected functionality and read files outside the intended directory via path traversal, with high confidentiality, integrity and availability impact per the CVSS vector.
Attack surface
Reachable over the network through the REST API (AV:N, AC:L, UI:N). The vector requires low privileges (PR:L), so some level of access is needed rather than being fully unauthenticated, though the description also claims authentication bypass.
Exploitation
Not listed in CISA KEV and no ransomware usage documented. EPSS is very high (0.73566, 99.4th percentile), and references are only vendor and third-party advisories with no public exploit tag.
What to do
- Apply the Cisco security advisory updates for UCS Director and UCS Director Express for Big Data.
- Restrict network access to the REST API to trusted management networks.
- Remove or disable unused API accounts and enforce least privilege on remaining ones.
- Monitor and log REST API requests for traversal patterns and unexpected authentication outcomes.
Detection
- Alert on REST API requests containing path traversal sequences such as ../ or encoded variants.
- Baseline normal API callers and flag new or unusual source IPs hitting the REST API.
- Review authentication logs for successful API sessions that bypass expected login flows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucsd-mult-vulns-UNfpdW4E | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-539/ | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucsd-mult-vulns-UNfpdW4E | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-539/ | Third Party AdvisoryVDB Entry |
Track CVE-2020-3239 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-3239), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.