Command Injection Vulnerability in Cisco Network Services Orchestrator
CVE-2018-0274
8.8HIGH
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 7 June 2018
What is CVE-2018-0274?
A security flaw in the CLI parser of Cisco Network Services Orchestrator allows authenticated remote attackers to execute arbitrary shell commands as the root user. This vulnerability, caused by insufficient input validation, enables attackers to inject malicious arguments into vulnerable commands. Successful exploitation can lead to full control over the affected system, posing significant risks to the network's integrity and security. Affected versions are 4.1 through 4.1.6.0, 4.2 through 4.2.4.0, 4.3 through 4.3.3.0, and 4.4 through 4.4.2.0.
Affected Version(s)
Cisco Network Services Orchestrator unknown Cisco Network Services Orchestrator unknown