← Vulnerability feed

Vulnerability record · CVE-2020-3371 · published 6 November 2020

CVE-2020-3371: Cisco integrated management controller os command injection vulnerability

Cisco · Integrated Management Controller

A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to inject and execute arbitrary commands at the underlying operating system level.

8.8 CVSS 3.1 High EPSS 1.9% · top 21.5% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to inject and execute arbitrary commands at the underlying operating system level.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3371 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-3470Cisco enterprise nfv infrastructure software memory buffer overflow vulnerabilityMultiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to exec…EPSS 4.8%9.8CVE-2018-15447Cisco integrated management controller sql injection vulnerabilityA vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker …EPSS 1.7%8.0CVE-2019-1632Cisco integrated management controller cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker t…EPSS 0.55%6.7CVE-2019-1879Cisco unified computing system os command injection vulnerabilityA vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands …EPSS 0.42%6.5CVE-2019-1627Cisco integrated management controller os command injection vulnerabilityA vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unautho…EPSS 1.2%6.1CVE-2021-1397Cisco integrated management controller open redirect vulnerabilityA vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote…EPSS 0.83%5.5CVE-2019-1628Cisco integrated management controller vulnerabilityA vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer over…EPSS 0.39%5.5CVE-2019-1630Cisco integrated management controller memory buffer overflow vulnerabilityA vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attack…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2020-3371), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.