Privilege Escalation Vulnerability in CA Unified Infrastructure Management by Broadcom
CVE-2020-28421

7.8HIGH

Key Information:

Vendor

Broadcom

Vendor
CVE Published:
23 November 2020

What is CVE-2020-28421?

CA Unified Infrastructure Management versions up to 20.1 contain a vulnerability within the robot (controller) component, enabling local attackers to elevate their privileges. This flaw allows unauthorized users to gain higher access rights than intended, potentially compromising sensitive operations within the infrastructure management system.

Affected Version(s)

CA Unified Infrastructure Management 20.1, 9.2.0, 9.1.0, 9.0.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.