CVE-2020-3171 is a local command injection vulnerability affecting Cisco FXOS Software and Cisco UCS Manager Software, including UCS 6400 Series Fabric Interconnects. An authenticated, local attacker can exploit insufficient input validation in the local management CLI to execute arbitrary commands. This vulnerability carries a CVSS score of 7.8 (High), indicating that an attacker can achieve high impact on confidentiality, integrity, and availability with low attack complexity and privileges. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it's not listed in CISA's KEV catalog, the vulnerability has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0\(1a\)aCPE matchmatch criteria | cpe:2.3:a:cisco:ucs_manager:4.0\(1a\)a:*:*:*:*:*:*:* | ||
2.4\(1.214\)CPE matchmatch criteria | cpe:2.3:o:cisco:fxos:2.4\(1.214\):*:*:*:*:*:*:* | ||
2.4\(1.216\)CPE matchmatch criteria | cpe:2.3:o:cisco:fxos:2.4\(1.216\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.