CVE-2022-20777: Cisco Enterprise NFV Infrastructure Software Vulnerabilities
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20777?
The severity of CVE-2022-20777 is critical with a severity value of 9.9.
What software is affected by CVE-2022-20777?
Cisco Enterprise NFV Infrastructure Software version up to 4.7.1 is affected by CVE-2022-20777.
What are the potential vulnerabilities of CVE-2022-20777?
The potential vulnerabilities of CVE-2022-20777 include escaping from the guest VM to the host machine, injecting commands at the root level, and leaking system data from the host to the VM.
Is there a fix available for CVE-2022-20777?
Yes, Cisco has released fixes for the vulnerabilities in Cisco Enterprise NFV Infrastructure Software. Please refer to the Cisco Security Advisory for more information.
Where can I find more information about CVE-2022-20777?
More information about CVE-2022-20777 can be found in the OrangeCERTCC security research advisory and the Cisco Security Advisory.