PT-2018-8722 · Linux+1 · Linux+1

Publicado

2018-05-17

·

Atualizado

2020-09-04

·

CVE-2018-0279

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco Enterprise NFV Infrastructure Software (NFVIS) versions 3.7.1 and earlier
Description: A vulnerability in the Secure Copy Protocol (SCP) server could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. This is due to improper input validation of command arguments, which an attacker could exploit by using crafted arguments when opening a connection to the affected device. An exploit could allow the attacker to gain shell access with a non-root user account to the underlying Linux operating system, potentially enabling execution of additional attacks that may have a significant impact on the affected system.
Recommendations: For Cisco Enterprise NFV Infrastructure Software (NFVIS) versions 3.7.1 and earlier, restrict access to the SCP server to minimize the risk of exploitation. Consider disabling the SCP server until a patch is available.

Correção

OS Command Injection

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-0279

Produtos afetados

Cisco Enterprise Nfv Infrastructure
Linux