VendorsCiscoenterprise_nfv_infrastructure_softwareall versions
Vulnerabilities

Cisco Enterprise

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

34CVEs
CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
Published 2025-04-16 · Analyzed
10.0KEVEPSS 0.988
CVE-2020-3470
Cisco Integrated Management Controller Multiple Remote Code Execution Vulnerabilities
Published 2020-11-18 · Modified
10.0EPSS 0.048
CVE-2019-1971
Cisco Enterprise NFV Infrastructure Software Command Injection Vulnerability
Published 2019-08-08 · Modified
10.0EPSS 0.036
CVE-2022-20780
Cisco Enterprise NFV Infrastructure Software Vulnerabilities
Published 2022-05-04 · Modified
9.9EPSS 0.112
CVE-2022-20777
Cisco Enterprise NFV Infrastructure Software Vulnerabilities
Published 2022-05-04 · Modified
9.9EPSS 0.111
CVE-2022-20779
Cisco Enterprise NFV Infrastructure Software Vulnerabilities
Published 2022-05-04 · Modified
9.9EPSS 0.105
CVE-2021-34746
Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
Published 2021-09-02 · Modified
9.8EPSS 0.177
CVE-2019-1895
Cisco Enterprise NFV Infrastructure Software VNC Authentication Bypass Vulnerability
Published 2019-08-07 · Modified
9.8EPSS 0.023
CVE-2018-0279
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation of command arguments. An attacker could exploit this vulnerability by using crafted arguments when opening a connection to the affected device. An exploit could allow the attacker to gain shell access with a non-root user account to the underlying Linux operating system on the affected device. Due to the system design, access to the Linux shell could allow execution of additional attacks that may have a significant impact on the affected system. This vulnerability affects Cisco devices that are running release 3.7.1, 3.6.3, or earlier releases of Cisco Enterprise NFV Infrastructure Software (NFVIS) when access to the SCP server is allowed on the affected device. Cisco NFVIS Releases 3.5.x and 3.6.x do allow access to the SCP server by default, while Cisco NFVIS Release 3.7.1 does not. Cisco Bug IDs: CSCvh25026.
Published 2018-05-17 · Modified
9.0EPSS 0.044
CVE-2019-1894
Cisco Enterprise NFV Infrastructure Software Arbitrary File Read and Write Vulnerability
Published 2019-07-06 · Modified
9.0EPSS 0.035
CVE-2020-3478
Cisco Enterprise NFV Infrastructure Software File Overwrite Vulnerability
Published 2020-09-04 · Modified
8.1EPSS 0.012
CVE-2021-1421
Cisco Enterprise NFV Infrastructure Software Command Injection Vulnerability
Published 2021-05-06 · Modified
7.8EPSS 0.007
CVE-2019-1893
Cisco Enterprise NFV Infrastructure Software Command Injection Vulnerability
Published 2019-07-06 · Modified
7.8EPSS 0.006
CVE-2022-20929
A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to insufficient cryptographic signature verification of upgrade files. An attacker could exploit this vulnerability by providing an administrator with an unauthentic upgrade file. A successful exploit could allow the attacker to fully compromise the Cisco NFVIS system.
Published 2023-03-08 · Modified
7.8EPSS 0.002
CVE-2019-1972
Cisco Enterprise NFV Infrastructure Software Privilege Escalation Vulnerability
Published 2019-08-08 · Modified
7.2EPSS 0.005
CVE-2020-3236
Cisco Enterprise NFV Infrastructure Software Path Traversal Vulnerability
Published 2020-06-18 · Modified
7.2EPSS 0.005
CVE-2020-3138
Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
Published 2020-02-19 · Modified
7.2EPSS 0.002
CVE-2019-1961
Cisco Enterprise NFV Infrastructure Software Web Portal Arbitrary File Read Vulnerability
Published 2019-08-08 · Modified
6.8EPSS 0.019
CVE-2019-1952
Cisco Enterprise NFV Infrastructure Software Path Traversal Vulnerability
Published 2019-08-08 · Modified
6.7EPSS 0.007
CVE-2020-3365
Cisco Enterprise NFV Infrastructure Software Path Traversal Vulnerability
Published 2020-09-04 · Modified
6.5EPSS 0.016
CVE-2019-1953
Cisco Enterprise NFV Infrastructure Software Password Recovery Vulnerability
Published 2019-08-08 · Modified
6.5EPSS 0.015
CVE-2019-1946
Cisco Enterprise NFV Infrastructure Software Web-Based Management Interface Authentication Bypass Vulnerability
Published 2019-08-08 · Modified
6.5EPSS 0.014
CVE-2026-20095
Cisco Integrated Management Controller Command Injection Vulnerability
Published 2026-04-01 · Analyzed
6.5EPSS 0.009
CVE-2026-20096
Cisco Integrated Management Controller Command Injection Vulnerability
Published 2026-04-01 · Analyzed
6.5EPSS 0.007
CVE-2026-20085
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Published 2026-04-01 · Analyzed
6.1EPSS 0.002
CVE-2021-1127
Cisco Enterprise NFV Infrastructure Software Cross-Site Scripting Vulnerability
Published 2021-01-13 · Modified
5.4EPSS 0.006
CVE-2019-1656
Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability
Published 2019-01-24 · Modified
5.3EPSS 0.004
CVE-2019-1973
Cisco Enterprise NFV Infrastructure Software Cross-site Scripting Vulnerability
Published 2019-08-08 · Modified
4.8EPSS 0.008
CVE-2026-20089
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Published 2026-04-01 · Analyzed
4.8EPSS 0.002
CVE-2026-20090
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Published 2026-04-01 · Analyzed
4.8EPSS 0.002
CVE-2026-20088
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Published 2026-04-01 · Analyzed
4.8EPSS 0.002
CVE-2026-20087
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Published 2026-04-01 · Analyzed
4.8EPSS 0.002
CVE-2019-1959
Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities
Published 2019-08-08 · Modified
4.4EPSS 0.004
CVE-2019-1960
Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities
Published 2019-08-08 · Modified
4.4EPSS 0.004