Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-4470

26
FAUCET Score

CVE-2020-4470 describes a critical arbitrary file upload vulnerability affecting IBM Spectrum Protect Plus versions 10.1.0 through 10.1.5. An authenticated attacker could exploit this flaw in the Administrative Console to upload and execute arbitrary code on the vulnerable server. With a CVSS score of 8.0 (High), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, its potential for remote code execution warrants attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.1.0, <= 10.1.5CPE matchmatch criteria
cpe:2.3:a:ibm:spectrum_protect_plus:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.1HIGH

CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.2
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.91%
Probability of exploitation in next 30 days
EPSS Percentile
77.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0191 is in the 92nd percentile among its peer group of 890 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (8)

esetvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
nxpvendor investigatingvia llm_extracted
omronvendor investigatingvia llm_extracted
openfirevendor investigatingvia llm_extracted
openstackvendor investigatingvia llm_extracted
pnpmvendor investigatingvia llm_extracted
twiliovendor investigatingvia llm_extracted

Vendor Advisories (8)

nxpllm-nxp-c9b24633beb0c2b8CRITICAL

IBM Spectrum Protect Plus Multiple Vulnerabilities

Jun 15, 2020
openstackllm-openstack-48b2b6a69384deaeCRITICAL

IBM Spectrum Protect Plus Multiple Vulnerabilities

Jun 15, 2020
hyperledgerllm-hyperledger-329d55d6f5dac67cCRITICAL

IBM Spectrum Protect Plus Multiple Vulnerabilities

Jun 15, 2020
pnpmllm-pnpm-68bfca9aefdf3ab2CRITICAL

IBM Spectrum Protect Plus Multiple Vulnerabilities

Jun 15, 2020
omronllm-omron-a3014c8ceaa7bbf0CRITICAL

IBM Spectrum Protect Plus Multiple Vulnerabilities

Jun 15, 2020
twiliollm-twilio-554b448c0f1e7754CRITICAL

IBM Spectrum Protect Plus Multiple Vulnerabilities

Jun 15, 2020
openfirellm-openfire-d64e4e7b03e493b6CRITICAL

IBM Spectrum Protect Plus Multiple Vulnerabilities

Jun 15, 2020
esetllm-eset-a01f401c4539e668CRITICAL

IBM Spectrum Protect Plus Multiple Vulnerabilities

Jun 15, 2020

References

exchange.xforce.ibmcloud.com / vulnerabilities/181725
VDB EntryVendor Advisory
ibm.com / support/pages/node/6221358
PatchVendor Advisory
tenable.com / security/research/tra-2020-37
Third Party Advisory