9.8
CVSSv3

CVE-2020-8012

Published: 18/02/2020 Updated: 29/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

broadcom unified infrastructure management

broadcom unified infrastructure management 20.1

Exploits

# Exploit Title: CA Unified Infrastructure Management Nimsoft 780 - Remote Buffer Overflow # Exploit Author: wetw0rk # Exploit Version: Public POC # Vendor Homepage: docopscacom/ca-unified-infrastructure-management/9-0-2/en # Software Version : 780 # Tested on: Windows 10 Pro (x64), Windows Server 2012 R2 Standard (x64) # CVE: CVE-2020- ...
Nimsoft nimcontroller version 780 suffers from an unauthenticated remote code execution vulnerability ...

Github Repositories

Vulnerability research on the CA UIM Nimbus protocol

CA Unified Infrastructure Management Research Research This repository will contain the majority of code written during my analysis of the Nimbus protocol Unfortunately during the madness of everything I lost a few snippets What originally spawned my curiosity to research this protocol was a recent pentest where we were able to get operating system information, installation d