← back
CVE-2022-20780

Cisco Enterprise NFV Infrastructure Software Vulnerabilities

CVSS 9.9 CRITICALEPSS 10.9%CWE-284
Vexday Risk Score
33Attention
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.9EPSS 10.9%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
04 May 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →