cisco-sa-20180516-nfvis-cli-command-injection: Cisco Enterprise NFV Infrastructure Software CLI Command Injection Vulnerability
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters in the CLI parser. An attacker could exploit this vulnerability by invoking a vulnerable CLI command with crafted malicious parameters. An exploit could allow the attacker to execute arbitrary commands with a non-root user account on the underlying Linux operating system of the affected device.
There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180516-nfvis-cli-command-injection
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20180516-nfvis-cli-command-injection?
The severity of cisco-sa-20180516-nfvis-cli-command-injection is considered high, as it allows for command injection by a high-privileged, authenticated local attacker.
How do I fix cisco-sa-20180516-nfvis-cli-command-injection?
To fix cisco-sa-20180516-nfvis-cli-command-injection, update your Cisco Enterprise NFV Infrastructure Software to the latest version that addresses this vulnerability.
Who is affected by cisco-sa-20180516-nfvis-cli-command-injection?
Cisco Enterprise NFV Infrastructure Software users with high-privileged local access are affected by cisco-sa-20180516-nfvis-cli-command-injection.
What type of attack can be performed due to cisco-sa-20180516-nfvis-cli-command-injection?
An authenticated, high-privileged local attacker can perform a command injection attack due to cisco-sa-20180516-nfvis-cli-command-injection.
What is the cause of cisco-sa-20180516-nfvis-cli-command-injection?
The cause of cisco-sa-20180516-nfvis-cli-command-injection is insufficient input validation of command parameters in the CLI parser.