Cisco Enterprise NFV Infrastructure Software是美国Cisco公司的一款一套企业级网络功能虚拟化软件。 Cisco Enterprise NFV Infrastructure Software存在跨站脚本漏洞,该漏洞源于对用户输入验证不足,可能导致经过身份验证的远程攻击者进行跨站脚本攻击,诱导用户点击特制链接,从而在用户浏览器中执行任意脚本代码或访问敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Enterprise NFV Infrastructure Software | 4.1.1 |
affected |
3.9.1 |
affected | ||
3.5.2 |
affected | ||
3.12.2 |
affected | ||
3.6.2 |
affected | ||
3.9.2 |
affected | ||
3.11.3 |
affected | ||
3.11.1 |
affected | ||
| … +64 more rows | |||
| Cisco | Cisco Unified Computing System (Standalone) | 4.0(2g) |
affected |
3.1(2i) |
affected | ||
3.1(1d) |
affected | ||
4.0(4i) |
affected | ||
4.1(1c) |
affected | ||
4.0(2c) |
affected | ||
4.0(1e) |
affected | ||
4.0(2h) |
affected | ||
| … +148 more rows | |||
| Cisco | Cisco Unified Computing System E-Series Software (UCSE) | 3.2.7 |
affected |
3.2.6 |
affected | ||
3.2.4 |
affected | ||
3.2.10 |
affected | ||
3.2.2 |
affected | ||
3.2.3 |
affected | ||
3.2.1 |
affected | ||
3.2.11.1 |
affected | ||
| … +23 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Enterprise NFV Infrastructure Software | 4.1.1 | - |
|
| Cisco | Cisco Unified Computing System (Standalone) | 4.0(2g) | - |
|
| Cisco | Cisco Unified Computing System E-Series Software (UCSE) | 3.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20304 | 9.9 CRITICAL | Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities |
| CVE-2026-20303 | 9.9 CRITICAL | Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities |
| CVE-2026-20272 | 9.8 CRITICAL | Cisco IOS XE Software Security Hardening Release |
| CVE-2026-20310 | 9.1 CRITICAL | Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File Ac |
| CVE-2026-20267 | 9.0 CRITICAL | Cisco IOS XE Software Security Hardening Release |
| CVE-2026-20312 | 8.8 HIGH | Cisco Catalyst SD-WAN Security Hardening Release - Information Disclosure Vulnerabilities |
| CVE-2026-20200 | 8.8 HIGH | Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulner |
| CVE-2026-20263 | 8.6 HIGH | Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability |
| CVE-2026-20268 | 8.6 HIGH | Cisco IOS XE Software Security Hardening Release |
| CVE-2026-20269 | 8.6 HIGH | Cisco IOS XE Software Security Hardening Release |
| CVE-2026-20270 | 8.6 HIGH | Cisco IOS XE Software Security Hardening Release |
| CVE-2026-20271 | 8.6 HIGH | Cisco IOS XE Software Security Hardening Release |
| CVE-2026-20273 | 8.6 HIGH | Cisco IOS XE Software Security Hardening Release |
| CVE-2026-20301 | 8.6 HIGH | Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Serv |
| CVE-2026-20313 | 7.7 HIGH | Cisco Catalyst SD-WAN Security Hardening Release - Memory Corruption Vulnerabilities |
| CVE-2026-20124 | 7.7 HIGH | Cisco IOS XE Software SNMP Denial of Service Vulnerability |
| CVE-2026-20294 | 6.5 MEDIUM | Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability |
| CVE-2026-20288 | 6.5 MEDIUM | Cisco IMC Remote Code Execution Vulnerability Remote Code Execution Vulnerability |
| CVE-2026-20311 | 6.3 MEDIUM | Cisco IOS XE Software Web UI Denial of Service Vulnerability |
| CVE-2026-20289 | 5.7 MEDIUM | Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet