4.6
CVSSv2

CVE-2018-0324

Published: 17/05/2018 Updated: 04/09/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local malicious user to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters in the CLI parser. An attacker could exploit this vulnerability by invoking a vulnerable CLI command with crafted malicious parameters. An exploit could allow the malicious user to execute arbitrary commands with a non-root user account on the underlying Linux operating system of the affected device. Cisco Bug IDs: CSCvi09723.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco network functions virtualization infrastructure 3.6.1

cisco network functions virtualization infrastructure 3.7.1

cisco network functions virtualization infrastructure 3.6.2

Vendor Advisories

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack The vulnerability is due to insufficient input validation of command parameters in the CLI parser An attacker could exploit this vulnerability by invoking a vulnerab ...