cisco-sa-nfvis-codex-shs4NhvS: Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker could exploit this vulnerability by providing a crafted upgrade file. A successful exploit could allow the attacker to upload crafted code to the affected device. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-codex-shs4NhvS
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-nfvis-codex-shs4NhvS?
The severity of cisco-sa-nfvis-codex-shs4NhvS is considered critical due to the potential for an authenticated attacker to install malicious files.
How do I fix cisco-sa-nfvis-codex-shs4NhvS?
To mitigate cisco-sa-nfvis-codex-shs4NhvS, ensure you apply the latest security updates provided by Cisco for Enterprise NFV Infrastructure Software.
Who is affected by cisco-sa-nfvis-codex-shs4NhvS?
The vulnerability cisco-sa-nfvis-codex-shs4NhvS affects users of Cisco Enterprise NFV Infrastructure Software.
What causes cisco-sa-nfvis-codex-shs4NhvS?
cisco-sa-nfvis-codex-shs4NhvS is caused by insufficient signature validation in the upgrade component of the software.
Can cisco-sa-nfvis-codex-shs4NhvS be exploited remotely?
No, cisco-sa-nfvis-codex-shs4NhvS requires local authenticated access for exploitation.