{"id":"CVE-2020-37070","title":"CloudMe 1.11.2 - Buffer Overflow (SEH,DEP,ASLR)","summary":"CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attackers can exploit the vulnerability by sending a specially crafted payload to the CloudMe…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-120"],"vendor":"CloudMe","product":"CloudMe","affected":["CloudMe 1.11.2"],"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-02-04T19:07:41.721809Z"},"exploitAvailable":true,"published":"2026-02-03","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:19:33.774Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2020-37070","references":[{"url":"https://www.exploit-db.com/exploits/48499","label":"ExploitDB-48499"},{"url":"https://www.cloudme.com/en","label":"CloudMe Official Homepage"},{"url":"https://www.vulncheck.com/advisories/cloudme-buffer-overflow-sehdepaslr","label":"VulnCheck Advisory: CloudMe 1.11.2 - Buffer Overflow (SEH,DEP,ASLR)"}],"tags":["cve.org","exploit-available"],"epss":0.00481,"epssPercentile":0.39182,"ingestedAt":"2026-10-01T15:48:17.878Z","slug":"CVE-2020-37070","body":"## Overview\n\nCloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attackers can exploit the vulnerability by sending a specially crafted payload to the CloudMe service running on port 8888, enabling remote code execution.\n\n## Affected\n\n- `CloudMe 1.11.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}