CVE-2018-0323Path Traversal in Cisco Enterprise NFV Infrastructure Software

CWE-22Path Traversal4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.7%
top 28.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 17
Latest updateMay 13

Description

A vulnerability in the web management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a path traversal attack on a targeted system. The vulnerability is due to insufficient validation of web request parameters. An attacker who has access to the web management interface of the affected application could exploit this vulnerability by sending a malicious web request to the affected device. A successful exploit could allow th

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5cisco/cisco_enterprise_nfv_infrastructure_softwareCisco Enterprise NFV Infrastructure Software

🔴Vulnerability Details

2
GHSA
GHSA-xfcp-57j3-q6c2: A vulnerability in the web management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker2022-05-13
CVEList
CVE-2018-0323: A vulnerability in the web management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker2018-05-17

📋Vendor Advisories

1
Cisco
Cisco Enterprise NFV Infrastructure Software Web Management Interface Path Traversal Vulnerability2018-05-16
CVE-2018-0323 — Path Traversal in Cisco | cvebase