CVE-2020-8010

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/02/2020
Last modified:
29/04/2022

Description

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:unified_infrastructure_management:*:*:*:*:*:*:*:* 9.20 (including)
cpe:2.3:a:broadcom:unified_infrastructure_management:*:*:*:*:*:*:*:* 20.3.0 (including) 20.3.3 (including)
cpe:2.3:a:broadcom:unified_infrastructure_management:20.1:*:*:*:*:*:*:*