← Vulnerability feed

Vulnerability record · CVE-2020-8012 · published 18 February 2020

CVE-2020-8012: CA Unified Infrastructure Management robot buffer overflow allows remote code execution

Broadcom · Unified Infrastructure Management

CA Unified Infrastructure Management (Nimsoft/UIM) versions 20.1, 20.3.x, and 9.20 and below contain a classic buffer overflow in the robot (controller) component. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the affected host. The flaw is rated critical and public exploit code exists, so exposure is significant for internet- or network-reachable robot endpoints.

9.8 CVSS 3.1 Critical EPSS 77% · top 0.5% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 7.5
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, and public exploit code makes this a high-urgency remote code execution flaw despite no KEV listing.

What it is

CA Unified Infrastructure Management (Nimsoft/UIM) versions 20.1, 20.3.x, and 9.20 and below contain a classic buffer overflow in the robot (controller) component. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the affected host. The flaw is rated critical and public exploit code exists, so exposure is significant for internet- or network-reachable robot endpoints.

Impact

Successful exploitation gives the attacker arbitrary code execution in the context of the robot service, which typically runs with high privileges on managed hosts. That can lead to full compromise of the monitored system and lateral movement across the UIM deployment.

Attack surface

The vulnerability is reachable over the network via the robot (controller) component, as reflected by the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required to attempt exploitation.

Exploitation

CVE-2020-8012 is not listed in CISA KEV, but public exploit code is referenced on Packet Storm and EPSS gives a 30-day probability of roughly 0.77 (99.5th percentile), indicating high likelihood of exploitation activity.

What to do

  • Apply the Broadcom/CA security advisory CA20200205-01 update for Unified Infrastructure Management and upgrade affected robot components to a fixed release.
  • Restrict network access to robot (controller) ports so only trusted management hosts can reach them; block exposure to untrusted networks and the internet.
  • Run the robot service with least privilege where supported and isolate UIM infrastructure from general user networks.
  • Monitor vendor advisories for updated fixed versions covering 20.1, 20.3.x, and 9.20 and below, and verify all endpoints are patched.
  • Where immediate patching is not possible, use network segmentation and host firewalls to limit reachable attack surface.

Detection

  • Monitor robot/controller service logs and host process telemetry for crashes, unexpected restarts, or anomalous child processes spawned by the robot service.
  • Inspect network traffic to robot ports for oversized or malformed payloads and unusual connection sources.
  • Alert on post-exploitation behavior such as new services, scheduled tasks, or outbound connections originating from UIM-managed hosts.
  • Use endpoint detection to flag memory corruption indicators and suspicious code execution in the context of the Nimsoft/UIM robot process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8012 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-8010CA Unified Infrastructure Management robot improper ACL allows remote command executionCA Unified Infrastructure Management (Nimsoft/UIM) versions 20.1, 20.3.x, and 9.20 and below contain improper ACL handling in the robot (controller) …EPSS 51%analysed7.8CVE-2020-28421Broadcom unified infrastructure management vulnerabilityCA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that allows local attackers to ele…EPSS 0.30%7.5CVE-2020-8011Broadcom unified infrastructure management null pointer dereference vulnerabilityCA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a null pointer dereference vulnerability in the robot (c…EPSS 2.2%5.5CVE-2025-43520Apple OS kernel memory corruption via malicious appA memory corruption flaw (classic buffer overflow) in Apple's kernel was fixed across iOS, iPadOS, macOS, tvOS, visionOS and watchOS. A malicious app…KEVEPSS 0.43%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed9.8CVE-2022-37055D-Link Go-RT-AC750 router buffer overflow in cgibin hnap_mainD-Link Go-RT-AC750 firmware revisions A v101b03 and B v200b02 contain a classic buffer overflow reachable through the cgibin hnap_main handler. The f…KEVEPSS 56%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.8CVE-2020-15069Sophos XG Firewall buffer overflow in HTTP/S BookmarksSophos XG Firewall 17.x through v17.5 MR12 contains a classic buffer overflow (CWE-120) reachable through the HTTP/S Bookmarks feature used for clien…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2020-8012), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.