Vulnerabilities > Cisco > Enterprise NFV Infrastructure Software

DATE CVE VULNERABILITY TITLE RISK
2019-01-24 CVE-2019-1656 Improper Input Validation vulnerability in Cisco Enterprise NFV Infrastructure Software 3.9.1
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell of the underlying Linux operating system on the affected device.
local
low complexity
cisco CWE-20
4.6
2018-05-17 CVE-2018-0279 OS Command Injection vulnerability in Cisco Enterprise NFV Infrastructure Software 3.7.1
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device.
network
low complexity
cisco CWE-78
critical
9.0