Vulnerability record · CVE-2020-8012 · published 18 February 2020
CVE-2020-8012: CA Unified Infrastructure Management robot buffer overflow allows remote code execution
Broadcom · Unified Infrastructure Management
CA Unified Infrastructure Management (Nimsoft/UIM) versions 20.1, 20.3.x, and 9.20 and below contain a classic buffer overflow in the robot (controller) component. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the affected host. The flaw is rated critical and public exploit code exists, so exposure is significant for internet- or network-reachable robot endpoints.
Description
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and public exploit code makes this a high-urgency remote code execution flaw despite no KEV listing.
What it is
CA Unified Infrastructure Management (Nimsoft/UIM) versions 20.1, 20.3.x, and 9.20 and below contain a classic buffer overflow in the robot (controller) component. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the affected host. The flaw is rated critical and public exploit code exists, so exposure is significant for internet- or network-reachable robot endpoints.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the robot service, which typically runs with high privileges on managed hosts. That can lead to full compromise of the monitored system and lateral movement across the UIM deployment.
Attack surface
The vulnerability is reachable over the network via the robot (controller) component, as reflected by the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required to attempt exploitation.
Exploitation
CVE-2020-8012 is not listed in CISA KEV, but public exploit code is referenced on Packet Storm and EPSS gives a 30-day probability of roughly 0.77 (99.5th percentile), indicating high likelihood of exploitation activity.
What to do
- Apply the Broadcom/CA security advisory CA20200205-01 update for Unified Infrastructure Management and upgrade affected robot components to a fixed release.
- Restrict network access to robot (controller) ports so only trusted management hosts can reach them; block exposure to untrusted networks and the internet.
- Run the robot service with least privilege where supported and isolate UIM infrastructure from general user networks.
- Monitor vendor advisories for updated fixed versions covering 20.1, 20.3.x, and 9.20 and below, and verify all endpoints are patched.
- Where immediate patching is not possible, use network segmentation and host firewalls to limit reachable attack surface.
Detection
- Monitor robot/controller service logs and host process telemetry for crashes, unexpected restarts, or anomalous child processes spawned by the robot service.
- Inspect network traffic to robot ports for oversized or malformed payloads and unusual connection sources.
- Alert on post-exploitation behavior such as new services, scheduled tasks, or outbound connections originating from UIM-managed hosts.
- Use endpoint detection to flag memory corruption indicators and suspicious code execution in the context of the Nimsoft/UIM robot process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-8012 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8012), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.