CVE-2020-3138
published 2020-02-19CVE-2020-3138: A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.21%
10.9th percentile
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker could exploit this vulnerability by providing a crafted upgrade file. A successful exploit could allow the attacker to upload crafted code to the affected device.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | enterprise_network_function_virtualization_infrastructure | <= 3.11.1 | — |
| cisco | enterprise_nfv_infrastructure | — | — |
| cisco | na | >= unspecified < n/a | n/a |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
vendor_cisco·2020-02-19·CVSS 6.7
CVE-2020-3138 [MEDIUM] CWE-347 Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
A vulnerability in the upgrade component of Cisco Enterprise NFV
Infrastructure Software (NFVIS) could allow an authenticated, local
attacker to install a malicious file when upgrading.
The vulnerability is due to insufficient signature validation. An
attacker could exploit this vulnerability by providing a crafted upgrade
file. A successful exploit could allow the attacker to upload crafted
code to the affected device.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-codex-shs4NhvS
Cisco
Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3138 Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
CVE-2020-3138: Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker could exploit this vulnerability by providing a crafted upgrade file. A successful exploit could allow the attacker to upload crafted code to the affected device. There are no
CVSS: 3.0
CWE: CWE-347, CWE-347
Bug IDs: CSCvr73802
GHSA
GHSA-9q6j-4fr7-7x67: A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to insta
ghsa_unreviewed·2022-05-24
CVE-2020-3138 [HIGH] GHSA-9q6j-4fr7-7x67: A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to insta
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker could exploit this vulnerability by providing a crafted upgrade file. A successful exploit could allow the attacker to upload crafted code to the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-19
Published