CVE-2020-37070
Severity CVSS v4.0:
HIGH
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
03/02/2026
Last modified:
03/02/2026
Description
CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attackers can exploit the vulnerability by sending a specially crafted payload to the CloudMe service running on port 8888, enabling remote code execution.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL



