CVE-2020-3239 describes multiple critical vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data. These flaws, including authentication bypass and directory traversal, allow a remote, low-privileged attacker to achieve high impact on confidentiality, integrity, and availability. With a CVSS score of 8.8 (HIGH) and a FAUCET Risk Score of 96/100, this vulnerability presents a significant risk. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it is not listed in the KEV catalog, it has garnered community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.0.0.0:*:*:*:*:*:*:* | ||
6.0.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.0.0.1:*:*:*:*:*:*:* | ||
6.0.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.0.1.0:*:*:*:*:*:*:* | ||
6.0.1.1CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.0.1.1:*:*:*:*:*:*:* | ||
6.0.1.2CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_director:6.0.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.