CVE-2022-20780
Cisco Enterprise NFV Infrastructure Software Vulnerabilities
Vexday Risk Score
33Attention
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.9EPSS 10.9%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
04 May 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Cisco · Cisco Enterprise NFV Infrastructure SoftwareWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →