CVE-2020-4241
33Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 66%
exploitation probability
66%top 1% of all CVEs
observed exploitation
nono source reports it
In short
IBM Spectrum Scale and Spectrum Protect Plus versions 10.1.0 through 10.1.5 have a flaw that lets authenticated attackers run arbitrary commands on the system by sending a specially crafted request. This is dangerous because it gives attackers full control over the affected system.
Technical detail
Remote authenticated attacker can execute arbitrary commands via specially crafted request to vulnerable versions of IBM Spectrum Scale and Spectrum Protect Plus (10.1.0–10.1.5). Requires valid credentials but does not require elevated privileges. Impact is code execution with system-level access.
Summary generated and translated by AI from the official description.
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175418.
CVSS:3.0/UI:N/I:H/S:U/A:H/AV:N/PR:L/AC:H/C:H/RL:O/RC:C/E:U
Affected products
IBM · Spectrum Protect Plus