Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCisco Enterprise Nfv Infrastructure Software
APPCisco< 4.7.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product
Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)
CVE-2022-20780CRITICAL9.9PL ✓same product
Cisco Enterprise NFVIS — ucieczka z VM, command injection i wyciek danych
CVE-2022-20779CRITICAL9.9PL ✓same product
Cisco Enterprise NFVIS — ucieczka z VM, command injection i wyciek danych
CVE-2021-34746CRITICAL9.8PL ✓same product
Cisco NFVIS: pominięcie uwierzytelnienia TACACS+ przez injection parametrów
CVE-2020-3470CRITICAL9.8PL ✓same product
RCE z uprawnieniami root w Cisco Integrated Management Controller (IMC)