CVE-2020-8012

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
18/02/2020
Last modified:
29/04/2022

Description

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:unified_infrastructure_management:*:*:*:*:*:*:*:* 9.20 (including)
cpe:2.3:a:broadcom:unified_infrastructure_management:*:*:*:*:*:*:*:* 20.3.0 (including) 20.3.3 (including)
cpe:2.3:a:broadcom:unified_infrastructure_management:20.1:*:*:*:*:*:*:*