VendorsCisconetwork_functions_virtualization_infrastructureall versions
Vulnerabilities

Cisco Network Functions Virtualization Infrastructure

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2018-0460
Cisco Enterprise NFV Infrastructure Software Information Disclosure Vulnerability
Published 2018-10-05 · Modified
6.8EPSS 0.019
CVE-2018-0459
Cisco Enterprise NFV Infrastructure Software Denial of Service Vulnerability
Published 2018-10-05 · Modified
6.8EPSS 0.018
CVE-2018-0324
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters in the CLI parser. An attacker could exploit this vulnerability by invoking a vulnerable CLI command with crafted malicious parameters. An exploit could allow the attacker to execute arbitrary commands with a non-root user account on the underlying Linux operating system of the affected device. Cisco Bug IDs: CSCvi09723.
Published 2018-05-17 · Modified
6.7EPSS 0.007
CVE-2018-0323
A vulnerability in the web management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a path traversal attack on a targeted system. The vulnerability is due to insufficient validation of web request parameters. An attacker who has access to the web management interface of the affected application could exploit this vulnerability by sending a malicious web request to the affected device. A successful exploit could allow the attacker to access sensitive information on the affected system. Cisco Bug IDs: CSCvh99631.
Published 2018-05-17 · Modified
6.5EPSS 0.018