Cisco Enterprise NFV Infrastructure Software(NFVIS)是美国思科(Cisco)公司的一套NVF基础架构软件平台。该平台可以通过中央协调器和控制器实现虚拟化服务的全生命周期管理。 Cisco Enterprise NFV Infrastructure 软件 4.0 及之前版本存在安全漏洞,经过身份验证的远程攻击者利用该漏洞能够从虚拟机中逃逸至宿主机,从而在 NFVIS 主机上获得未经授权的root级访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Enterprise NFV Infrastructure Software | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-20779 | 9.9 CRITICAL | Cisco Enterprise NFV Infrastructure Software Vulnerabilities |
| CVE-2022-20780 | 9.9 CRITICAL | Cisco Enterprise NFV Infrastructure Software Vulnerabilities |
| CVE-2022-20770 | 8.6 HIGH | ClamAV CHM File Parsing Denial of Service Vulnerability Affecting Cisco Products: April 20 |
| CVE-2022-20771 | 7.5 HIGH | ClamAV TIFF File Parsing Denial of Service Vulnerability Affecting Cisco Products: April 2 |
| CVE-2022-20785 | 7.5 HIGH | ClamAV HTML Scanning Memory Leak Vulnerability Affecting Cisco Products: April 2022 |
| CVE-2022-20764 | 6.5 MEDIUM | Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities |
| CVE-2022-20794 | 6.5 MEDIUM | Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities |
| CVE-2022-20796 | 6.5 MEDIUM | ClamAV Truncated File Denial of Service Vulnerability Affecting Cisco Products: April 2022 |
| CVE-2022-20753 | 4.7 MEDIUM | Cisco Small Business RV Series Routers Remote Code Execution Vulnerability |
| CVE-2022-20801 | 4.7 MEDIUM | Cisco Small Business RV Series Routers Command Injection Vulnerabilities |
| CVE-2022-20799 | 4.7 MEDIUM | Cisco Small Business RV Series Routers Command Injection Vulnerabilities |
| CVE-2022-20734 | 4.4 MEDIUM | Cisco SD-WAN vManage Software Information Disclosure Vulnerability |
No comments yet