Back

MEDIUM

Cisco Enterprise NFV Infrastructure Software Remote Code Execution Vulnerability

Published Feb 19, 2020

Description

A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker could exploit this vulnerability by providing a crafted upgrade file. A successful exploit could allow the attacker to upload crafted code to the affected device.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published Feb 19, 2020
Updated Nov 15, 2024
Reserved Dec 12, 2019
CISA Vulnrichment
Updated Nov 15, 2024
NVD
Status Modified
Modified Aug 24, 2026
Red Hat
Severity n/a
Public date n/a