Networking-Forums.com

Professional Discussions => Vendor Advisories => Topic started by: Netwörkheäd on May 10, 2022, 06:20:46 PM

Title: Cisco Security Advisory - Cisco Enterprise NFV Infrastructure Software Vulnerabilities
Post by: Netwörkheäd on May 10, 2022, 06:20:46 PM
Cisco Enterprise NFV Infrastructure Software Vulnerabilities

<p> Multiple vulnerabilities in Cisco&nbsp;Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the <em>root</em> level, or leak system data from the host to the VM.</p>
<p>For more information about these vulnerabilities, see the <a href="#details">Details</a> section of this advisory.</p>
<p>Cisco&nbsp;has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.</p>
<p>This advisory is available at the following link:<br><a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-NFVIS-MUL-7DySRX9" target="_blank">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-NFVIS-MUL-7DySRX9</a></p>
     
         
Security Impact Rating:  Critical
   
   
       
CVE: CVE-2022-20777,CVE-2022-20779,CVE-2022-20780
Source: Cisco Enterprise NFV Infrastructure Software Vulnerabilities (https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-NFVIS-MUL-7DySRX9?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Enterprise%20NFV%20Infrastructure%20Software%20Vulnerabilities&vs_k=1)