Back

MEDIUM

Cisco Enterprise NFV Infrastructure Software Path Traversal Vulnerability

Published Sep 4, 2020

Description

A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories. The vulnerability is due to a flaw in the logic that governs directory permissions. An attacker could exploit this vulnerability by using capabilities that are not controlled by the role-based access control (RBAC) mechanisms of the software. A successful exploit could allow the attacker to overwrite files on an affected device.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published Sep 4, 2020
Updated Nov 13, 2024
Reserved Dec 12, 2019
CISA Vulnrichment
Updated Nov 13, 2024
NVD
Status Modified
Modified Aug 24, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner cisco
Published Sep 4, 2020
Updated Nov 13, 2024
Exploited since n/a
EUVD-2020-24636