← Vulnerability feed

Vulnerability record · CVE-2020-4211 · published 24 February 2020

CVE-2020-4211: IBM Spectrum Protect Plus OS command injection via crafted HTTP command

Ibm · Spectrum Protect

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 contain an OS command injection flaw (CWE-78) reachable through a specially crafted HTTP command. A remote, unauthenticated attacker can execute arbitrary commands on the system, making this a critical pre-auth remote code execution issue in a backup and data protection product.

9.8 CVSS 3.1 Critical EPSS 71% · top 0.6% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS score, makes this a top remediation priority despite no KEV listing.

What it is

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 contain an OS command injection flaw (CWE-78) reachable through a specially crafted HTTP command. A remote, unauthenticated attacker can execute arbitrary commands on the system, making this a critical pre-auth remote code execution issue in a backup and data protection product.

Impact

An attacker gains arbitrary command execution on the affected server, which can lead to full host compromise and access to backed-up data and credentials managed by the product.

Attack surface

Reached over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not identify the specific endpoint or parameter involved.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.711 (99.4th percentile), indicating substantial observed likelihood of exploitation activity; reference tags are vendor advisory, patch and third-party advisory only, with no public exploit tag.

What to do

  • Apply the IBM fix referenced in the vendor support page (node/3178863) for Spectrum Protect Plus 10.1.0 and 10.1.5, or upgrade to a fixed release.
  • Restrict network access to the Spectrum Protect Plus management interface to trusted administrative networks; do not expose it to the internet.
  • Place the appliance behind a reverse proxy or firewall rules that limit which HTTP methods and paths are reachable from untrusted segments.
  • Monitor and rotate credentials and secrets stored or managed by Spectrum Protect Plus in case of prior compromise.
  • If patching cannot be done immediately, isolate affected instances and treat them as high-risk until remediated.

Detection

  • Inspect HTTP access logs for anomalous or malformed requests to Spectrum Protect Plus management endpoints, especially shell metacharacters in parameters.
  • Alert on unexpected child processes spawned by the Spectrum Protect Plus web or application service (for example shells or system utilities).
  • Monitor for outbound connections from the appliance to unfamiliar hosts, which may indicate command-and-control or data exfiltration after exploitation.
  • Review host and application logs for command execution errors or unusual process trees on the Spectrum Protect Plus server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-4211 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-4415Ibm spectrum protect improper input validation vulnerabilityIBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote…EPSS 8.1%9.8CVE-2020-4210Ibm spectrum protect os command injection vulnerabilityIBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …EPSS 15%9.8CVE-2020-4212Ibm spectrum protect improper input validation vulnerabilityIBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …EPSS 15%9.8CVE-2020-4213Ibm spectrum protect os command injection vulnerabilityIBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …EPSS 15%9.8CVE-2020-4222Ibm spectrum protect os command injection vulnerabilityIBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP …EPSS 15%8.8CVE-2022-22394Ibm spectrum protect vulnerabilityThe IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access co…EPSS 2.2%7.8CVE-2019-4267Ibm spectrum protect memory buffer overflow vulnerabilityThe IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow execution of arbitrary code on the lo…EPSS 0.44%7.5CVE-2020-4559Ibm spectrum protect improper input validation vulnerabilityIBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2020-4211), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.