← Vulnerability feed

Vulnerability record · CVE-2020-3470 · published 18 November 2020

CVE-2020-3470: Cisco enterprise nfv infrastructure software memory buffer overflow vulnerability

Cisco · Enterprise Nfv Infrastructure Software

Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).

9.8 CVSS 3.1 Critical EPSS 4.8% · top 8.4% CWE-119 · Memory buffer overflowCWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 10.0
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the API subsystem of an affected system. When this request is processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the underlying operating system (OS).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3470 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed9.9CVE-2022-20777Cisco enterprise nfv infrastructure software improper access control vulnerabilityMultiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM…EPSS 11%9.8CVE-2021-34746Cisco enterprise nfv infrastructure software improper authentication vulnerabilityA vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) cou…EPSS 18%9.8CVE-2019-1971Cisco enterprise nfv infrastructure software os command injection vulnerabilityA vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform …EPSS 3.6%9.8CVE-2019-1895Cisco enterprise nfv infrastructure software missing authentication for critical function vulnerabilityA vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an …EPSS 2.3%9.8CVE-2018-15447Cisco integrated management controller sql injection vulnerabilityA vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker …EPSS 1.7%8.8CVE-2022-20779Cisco enterprise nfv infrastructure software improper access control vulnerabilityMultiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM…EPSS 10%8.8CVE-2020-3371Cisco integrated management controller os command injection vulnerabilityA vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code …EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2020-3470), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.