Command Injection Vulnerability in Cisco Network Services Orchestrator
CVE-2018-0274

8.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
7 June 2018

Summary

A security flaw in the CLI parser of Cisco Network Services Orchestrator allows authenticated remote attackers to execute arbitrary shell commands as the root user. This vulnerability, caused by insufficient input validation, enables attackers to inject malicious arguments into vulnerable commands. Successful exploitation can lead to full control over the affected system, posing significant risks to the network's integrity and security. Affected versions are 4.1 through 4.1.6.0, 4.2 through 4.2.4.0, 4.3 through 4.3.3.0, and 4.4 through 4.4.2.0.

Affected Version(s)

Cisco Network Services Orchestrator unknown Cisco Network Services Orchestrator unknown

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.