Command Injection Vulnerability in Cisco Network Services Orchestrator
CVE-2018-0274
8.8HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 7 June 2018
Summary
A security flaw in the CLI parser of Cisco Network Services Orchestrator allows authenticated remote attackers to execute arbitrary shell commands as the root user. This vulnerability, caused by insufficient input validation, enables attackers to inject malicious arguments into vulnerable commands. Successful exploitation can lead to full control over the affected system, posing significant risks to the network's integrity and security. Affected versions are 4.1 through 4.1.6.0, 4.2 through 4.2.4.0, 4.3 through 4.3.3.0, and 4.4 through 4.4.2.0.
Affected Version(s)
Cisco Network Services Orchestrator unknown Cisco Network Services Orchestrator unknown
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved