CVE-2022-20780: Cisco Enterprise NFV Infrastructure Software Vulnerabilities
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20780?
The severity of CVE-2022-20780 is critical (CVSS score 7.4).
What is CVE-2022-20780?
CVE-2022-20780 refers to multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) that could allow an attacker to escape from the guest VM to the host machine, inject commands at the root level, or leak system data from the host to the VM.
How can an attacker exploit CVE-2022-20780?
An attacker can exploit CVE-2022-20780 by escaping from the guest VM to the host machine, injecting commands at the root level, or leaking system data from the host to the VM.
Is there a fix available for CVE-2022-20780?
Yes, Cisco has released patches to address the vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS). It is recommended to update to version 4.7.2 or later.
Where can I find more information about CVE-2022-20780?
You can find more information about CVE-2022-20780 on the Cisco Security Advisory page and the Orange Cyberdefense security research page.