CVE-2018-0323 — Path Traversal in Cisco Enterprise NFV Infrastructure Software
Severity
6.5MEDIUMNVD
EPSS
0.7%
top 28.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateMay 13
Description
A vulnerability in the web management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a path traversal attack on a targeted system. The vulnerability is due to insufficient validation of web request parameters. An attacker who has access to the web management interface of the affected application could exploit this vulnerability by sending a malicious web request to the affected device. A successful exploit could allow th…
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages2 packages
▶CVEListV5cisco/cisco_enterprise_nfv_infrastructure_softwareCisco Enterprise NFV Infrastructure Software
🔴Vulnerability Details
2GHSA▶
GHSA-xfcp-57j3-q6c2: A vulnerability in the web management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker↗2022-05-13
CVEList▶
CVE-2018-0323: A vulnerability in the web management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker↗2018-05-17
📋Vendor Advisories
1Cisco▶
Cisco Enterprise NFV Infrastructure Software Web Management Interface Path Traversal Vulnerability↗2018-05-16