CVE-2020-3138
published 2020-02-19CVE-2020-3138: A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.21%
11.1th percentile
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker could exploit this vulnerability by providing a crafted upgrade file. A successful exploit could allow the attacker to upload crafted code to the affected device.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | enterprise_nfv_infrastructure | — | — |
| cisco | enterprise_nfv_infrastructure_software | <= 3.11.1 | — |
| cisco | na | >= unspecified < n/a | n/a |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco Enterprise NFV Infrastructure Software Signature Validation signature verification (cisco-sa-nfvis-codex-shs4NhvS)
vuldb·2026-08-24·CVSS 6.7
CVE-2020-3138 [MEDIUM] Cisco Enterprise NFV Infrastructure Software Signature Validation signature verification (cisco-sa-nfvis-codex-shs4NhvS)
A vulnerability classified as critical has been found in Cisco Enterprise NFV Infrastructure Software. Affected by this vulnerability is an unknown functionality of the component Signature Validation. The manipulation leads to improper verification of cryptographic signature.
This vulnerability is traded as CVE-2020-3138. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-9q6j-4fr7-7x67: A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to insta
ghsa_unreviewed·2022-05-24
CVE-2020-3138 [HIGH] GHSA-9q6j-4fr7-7x67: A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to insta
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker could exploit this vulnerability by providing a crafted upgrade file. A successful exploit could allow the attacker to upload crafted code to the affected device.
Cisco
Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
vendor_cisco·2020-02-19·CVSS 6.7
CVE-2020-3138 [MEDIUM] CWE-347 Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
A vulnerability in the upgrade component of Cisco Enterprise NFV
Infrastructure Software (NFVIS) could allow an authenticated, local
attacker to install a malicious file when upgrading.
The vulnerability is due to insufficient signature validation. An
attacker could exploit this vulnerability by providing a crafted upgrade
file. A successful exploit could allow the attacker to upload crafted
code to the affected device.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-codex-shs4NhvS
Cisco
Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3138 Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
CVE-2020-3138: Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker could exploit this vulnerability by providing a crafted upgrade file. A successful exploit could allow the attacker to upload crafted code to the affected device. There are no
CVSS: 3.0
CWE: CWE-347, CWE-347
Bug IDs: CSCvr73802
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-19
Published