cbcvebase.

Cisco Enterprise Nfv Infrastructure Software vulnerabilities

38 known vulnerabilities affecting cisco/cisco_enterprise_nfv_infrastructure_software.

Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH9MEDIUM24

Vulnerabilities

Page 2 of 2
CVE-2022-20929P3HIGHCVSS 7.8v3.5.1v3.5.2+31 more2023-03-10
CVE-2022-20929 [HIGH] CWE-347 CVE-2022-20929: A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Softwar A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to insufficient cryptographic signature verification of upgrade files. An attacker could exploit this vulnerability by
nvd
CVE-2018-0459P3MEDIUMCVSS 6.5vn/a2018-10-05
CVE-2018-0459 [MEDIUM] CWE-285 CVE-2018-0459: A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Softwar A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerability is due to insufficient server-side authorization checks. An attacker who is logged in to the web-based management interface as
nvd
CVE-2019-1972P3MEDIUMCVSS 6.7≥ unspecified, < n/a2019-08-08
CVE-2019-1972 [MEDIUM] CWE-264 CVE-2019-1972: A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow an authenticated, local attacker with valid administrator-level credentials to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient restrictions during the execution of an
nvd
CVE-2019-1952P4MEDIUMCVSS 6.7≥ unspecified, < 3.10.12019-08-08
CVE-2019-1952 [MEDIUM] CWE-22 CVE-2019-1952: A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an au A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to overwrite or read arbitrary files. The attacker would need valid administrator privilege-level credentials. This vulnerability is due to improper input validation of CLI command arguments. An attacker could exploit this vul
nvd
CVE-2020-3236P4MEDIUMCVSS 6.7vn/a2020-06-18
CVE-2020-3236 [MEDIUM] CWE-22 CVE-2020-3236: A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an au A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files. The attacker would need valid administrative credentials. This vulnerability is due to improper input validation of CLI comman
nvd
CVE-2019-1961P4MEDIUMCVSS 4.9≥ unspecified, < n/a2019-08-08
CVE-2019-1961 [MEDIUM] CWE-532 CVE-2019-1961: A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to the improper input validation of tar packages uploaded through the Web Portal to the Image Repository. An attacker could
nvd
CVE-2026-20085P4MEDIUMCVSS 6.1v4.1.1v3.9.1+67 more2026-04-01
CVE-2026-20085 [MEDIUM] CWE-79 CVE-2026-20085: A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, r A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a
nvd
CVE-2021-1127P4MEDIUMCVSS 5.4vn/a2021-01-13
CVE-2021-1127 [MEDIUM] CWE-79 CVE-2021-1127: A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Softwar A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to improper input validation of log file content stored on the affected
nvd
CVE-2019-1656P4MEDIUMCVSS 5.3vn/a2019-01-24
CVE-2019-1656 [MEDIUM] CWE-20 CVE-2019-1656: A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an au A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation in the affected software. An attacker could exploit this vulnerability by sending craft
nvd
CVE-2018-0462P4MEDIUMCVSS 4.9vn/a2018-10-05
CVE-2018-0462 [MEDIUM] CWE-20 CVE-2018-0462: A vulnerability in the user management functionality of Cisco Enterprise NFV Infrastructure Software A vulnerability in the user management functionality of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a denial of service (DoS) attack against an affected system. The vulnerability is due to insufficient validation of user-provided input. An attacker could exploit this vulnerability by log
nvd
CVE-2026-20089P4MEDIUMCVSS 4.8v4.1.1v3.9.1+67 more2026-04-01
CVE-2026-20089 [MEDIUM] CWE-79 CVE-2026-20089: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2026-20090P4MEDIUMCVSS 4.8v4.1.1v3.9.1+67 more2026-04-01
CVE-2026-20090 [MEDIUM] CWE-79 CVE-2026-20090: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2026-20088P4MEDIUMCVSS 4.8v4.1.1v3.9.1+67 more2026-04-01
CVE-2026-20088 [MEDIUM] CWE-79 CVE-2026-20088: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2026-20087P4MEDIUMCVSS 4.8v4.1.1v3.9.1+68 more2026-04-01
CVE-2026-20087 [MEDIUM] CWE-79 CVE-2026-20087: A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an aff
nvd
CVE-2019-12623P4MEDIUMCVSS 4.3≥ unspecified, < 3.12.12019-08-21
CVE-2019-12623 [MEDIUM] CWE-538 CVE-2019-12623: A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affected system. The vulnerability is due to the web server responding with different error codes for existing and non-existing files. An
nvd
CVE-2019-1973P4MEDIUMCVSS 4.8≥ unspecified, < n/a2019-08-08
CVE-2019-1973 [MEDIUM] CWE-79 CVE-2019-1973: A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to improper input validation of log file content stored on the affected device. An attacker co
nvd
CVE-2019-1960P4MEDIUMCVSS 4.4≥ unspecified, < n/a2019-08-08
CVE-2019-1960 [MEDIUM] CWE-20 CVE-2019-1960: Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an auth Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2019-1959P4MEDIUMCVSS 4.4≥ unspecified, < n/a2019-08-08
CVE-2019-1959 [MEDIUM] CWE-20 CVE-2019-1959: Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an auth Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
Cisco Enterprise Nfv Infrastructure Software vulnerabilities | cvebase