CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2022-20777

CVSS 9.9v3.1pub. 2022-05-04upd. 2024-11-21

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Cisco Enterprise Nfv Infrastructure Software

    APP
    Cisco
    < 4.7.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)

CVE-2022-20780CRITICAL9.9PL ✓same product

Cisco Enterprise NFVIS — ucieczka z VM, command injection i wyciek danych

CVE-2022-20779CRITICAL9.9PL ✓same product

Cisco Enterprise NFVIS — ucieczka z VM, command injection i wyciek danych

CVE-2021-34746CRITICAL9.8PL ✓same product

Cisco NFVIS: pominięcie uwierzytelnienia TACACS+ przez injection parametrów

CVE-2020-3470CRITICAL9.8PL ✓same product

RCE z uprawnieniami root w Cisco Integrated Management Controller (IMC)