Lucene search

K
ciscoCiscoCISCO-SA-20180516-NFVIS
HistoryMay 16, 2018 - 4:00 p.m.

Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability

2018-05-1616:00:00
tools.cisco.com
70

EPSS

0.002

Percentile

55.0%

A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device.

The vulnerability is due to improper input validation of command arguments. An attacker could exploit this vulnerability by using crafted arguments when opening a connection to the affected device. An exploit could allow the attacker to gain shell access with a non-root user account to the underlying Linux operating system on the affected device.

Due to the system design, access to the Linux shell could allow execution of additional attacks that may have a significant impact on the affected system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180516-nfvis [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180516-nfvis”]

Affected configurations

Vulners
Node
ciscoenterprise_nfv_infrastructure_softwareMatchany
OR
ciscoenterprise_nfv_infrastructure_softwareMatchany
VendorProductVersionCPE
ciscoenterprise_nfv_infrastructure_softwareanycpe:2.3:a:cisco:enterprise_nfv_infrastructure_software:any:*:*:*:*:*:*:*

EPSS

0.002

Percentile

55.0%

Related for CISCO-SA-20180516-NFVIS