Vulnerability record · CVE-2020-4211 · published 24 February 2020
CVE-2020-4211: IBM Spectrum Protect Plus OS command injection via crafted HTTP command
Ibm · Spectrum Protect
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 contain an OS command injection flaw (CWE-78) reachable through a specially crafted HTTP command. A remote, unauthenticated attacker can execute arbitrary commands on the system, making this a critical pre-auth remote code execution issue in a backup and data protection product.
Description
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS score, makes this a top remediation priority despite no KEV listing.
What it is
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 contain an OS command injection flaw (CWE-78) reachable through a specially crafted HTTP command. A remote, unauthenticated attacker can execute arbitrary commands on the system, making this a critical pre-auth remote code execution issue in a backup and data protection product.
Impact
An attacker gains arbitrary command execution on the affected server, which can lead to full host compromise and access to backed-up data and credentials managed by the product.
Attack surface
Reached over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not identify the specific endpoint or parameter involved.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.711 (99.4th percentile), indicating substantial observed likelihood of exploitation activity; reference tags are vendor advisory, patch and third-party advisory only, with no public exploit tag.
What to do
- Apply the IBM fix referenced in the vendor support page (node/3178863) for Spectrum Protect Plus 10.1.0 and 10.1.5, or upgrade to a fixed release.
- Restrict network access to the Spectrum Protect Plus management interface to trusted administrative networks; do not expose it to the internet.
- Place the appliance behind a reverse proxy or firewall rules that limit which HTTP methods and paths are reachable from untrusted segments.
- Monitor and rotate credentials and secrets stored or managed by Spectrum Protect Plus in case of prior compromise.
- If patching cannot be done immediately, isolate affected instances and treat them as high-risk until remediated.
Detection
- Inspect HTTP access logs for anomalous or malformed requests to Spectrum Protect Plus management endpoints, especially shell metacharacters in parameters.
- Alert on unexpected child processes spawned by the Spectrum Protect Plus web or application service (for example shells or system utilities).
- Monitor for outbound connections from the appliance to unfamiliar hosts, which may indicate command-and-control or data exfiltration after exploitation.
- Review host and application logs for command execution errors or unusual process trees on the Spectrum Protect Plus server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/175022 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/3178863 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-273/ | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/175022 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/3178863 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-273/ | Third Party AdvisoryVDB Entry |
Track CVE-2020-4211 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-4211), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.