Логотип exploitDog
bind:CVE-2020-3236
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-3236

Количество 3

Количество 3

nvd логотип

CVE-2020-3236

больше 5 лет назад

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files. The attacker would need valid administrative credentials. This vulnerability is due to improper input validation of CLI command arguments. An attacker could exploit this vulnerability by using path traversal techniques when executing a vulnerable command. A successful exploit could allow the attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files on an affected device.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-hg4p-q65f-q54v

больше 3 лет назад

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files. The attacker would need valid administrative credentials. This vulnerability is due to improper input validation of CLI command arguments. An attacker could exploit this vulnerability by using path traversal techniques when executing a vulnerable command. A successful exploit could allow the attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files on an affected device.

EPSS: Низкий
fstec логотип

BDU:2020-03124

больше 5 лет назад

Уязвимость компонента CLI программного обеспечения инфраструктуры Cisco Enterprise NFV Infrastructure Software, позволяющая нарушителю получить доступ к базовой операционной системе и перезаписать или прочитать произвольные файлы

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-3236

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files. The attacker would need valid administrative credentials. This vulnerability is due to improper input validation of CLI command arguments. An attacker could exploit this vulnerability by using path traversal techniques when executing a vulnerable command. A successful exploit could allow the attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files on an affected device.

CVSS3: 6.7
0%
Низкий
больше 5 лет назад
github логотип
GHSA-hg4p-q65f-q54v

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files. The attacker would need valid administrative credentials. This vulnerability is due to improper input validation of CLI command arguments. An attacker could exploit this vulnerability by using path traversal techniques when executing a vulnerable command. A successful exploit could allow the attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files on an affected device.

0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-03124

Уязвимость компонента CLI программного обеспечения инфраструктуры Cisco Enterprise NFV Infrastructure Software, позволяющая нарушителю получить доступ к базовой операционной системе и перезаписать или прочитать произвольные файлы

CVSS3: 6.7
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу