ZeroHour

CVE-2020-4428

KEVniche

Authenticated Command Injection RCE in IBM Data Risk Manager 2.0.x

CISA: IBM Data Risk Manager Remote Code Execution Vulnerability

CVSS 3.1
9.1 critical
EPSS
62%p99
Published
()
KEV added
AI analysis

IBM Data Risk Manager versions 2.0.1, 2.0.2, 2.0.3 and 2.0.4 contain an OS command injection flaw (CWE-78) that lets a remote attacker who has already authenticated to the appliance execute arbitrary commands. Because the CVSS vector rates privileges required as high, triggering the flaw requires privileged, administrator-level credentials to the product, after which the injected commands run outside the application context on the underlying appliance operating system (scope is changed per the CVSS vector). Successful exploitation yields full compromise of the host, with high impact to confidentiality, integrity and availability. Any organization running Data Risk Manager 2.0.1 through 2.0.4 is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known exploitation in the wild, EPSS puts its 30-day exploitation probability at roughly 62% (99th percentile), and no public proof-of-concept is known.

What to do: Upgrade every Data Risk Manager deployment running 2.0.1, 2.0.2, 2.0.3 or 2.0.4 to the fixed release per IBM's security bulletin, as this is the required action under CISA's KEV listing. Because exploitation requires high-privileged credentials, review and rotate appliance administrator credentials and hunt for signs of unexpected command execution on the appliance host. Restrict the appliance's management interface to trusted administrative networks rather than exposing it to the internet.

Affected
IBM Data Risk Manager2.0.1, 2.0.2, 2.0.3, 2.0.4
Estimated exposure
nichelikely a few thousand enterprise deployments worldwide, with only a few hundred instances internet-exposed (estimate) — Data Risk Manager is a specialized IBM security-analytics appliance sold to large enterprises rather than mass-market software, so the global install base is plausibly in the low thousands of deployments and public internet scans typically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.

CISA Known Exploited Vulnerability
Affected
IBM Data Risk Manager
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
ibm
Products
data risk manager
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.