Vulnerability record · CVE-2020-8010 · published 18 February 2020
CVE-2020-8010: CA Unified Infrastructure Management robot improper ACL allows remote command execution
Broadcom · Unified Infrastructure Management
CA Unified Infrastructure Management (Nimsoft/UIM) versions 20.1, 20.3.x, and 9.20 and below contain improper ACL handling in the robot (controller) component. A remote, unauthenticated attacker can execute commands, read from, or write to the target system. The flaw is rated critical and affects a core management component, so exposure is significant wherever the robot service is reachable.
Description
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, high EPSS, and public exploit references make this a high-urgency remote compromise risk.
What it is
CA Unified Infrastructure Management (Nimsoft/UIM) versions 20.1, 20.3.x, and 9.20 and below contain improper ACL handling in the robot (controller) component. A remote, unauthenticated attacker can execute commands, read from, or write to the target system. The flaw is rated critical and affects a core management component, so exposure is significant wherever the robot service is reachable.
Impact
An attacker gains the ability to run arbitrary commands and read or write files on the target host, effectively full control of the affected system. This can lead to data theft, configuration tampering, or use of the host as a pivot into the managed environment.
Attack surface
The vulnerability is network-reachable via the robot (controller) component, with the CVSS vector indicating no authentication and no user interaction required. Any host running the affected robot service and reachable on the network is a candidate target.
Exploitation
The record is not listed in CISA KEV, but EPSS is high (about 0.51, 98.9th percentile) and references include an Exploit-tagged third-party advisory, indicating public exploit material exists. No ransomware association is documented.
What to do
- Apply the vendor security notice CA20200205-01 fixes for CA Unified Infrastructure Management; upgrade affected 9.20 and below, 20.1, and 20.3.x deployments to a patched release.
- Restrict network access to the robot (controller) service to trusted management subnets and block it from untrusted networks.
- Audit ACL configuration on robot components to ensure only intended principals can issue commands or access files.
- Monitor vendor advisories for updated guidance and re-check exposure after patching.
- Where patching is delayed, isolate affected hosts and limit their reachability to reduce lateral movement risk.
Detection
- Monitor robot/controller service logs for unexpected command execution or file access from remote sources.
- Alert on network connections to the robot service port from hosts outside the expected management subnet.
- Baseline and review ACL changes on robot components for unauthorized modifications.
- Hunt for anomalous process creation or file writes on UIM-managed hosts that correlate with robot service activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-8010 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8010), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.