PT-2021-3906 · Cisco · Cisco Enterprise Nfv Infrastructure

Cyrille Chatras

·

Published

2021-09-01

·

Updated

2022-09-12

·

CVE-2021-34746

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Enterprise NFV Infrastructure Software (NFVIS) (affected versions not specified)
Description A vulnerability in the TACACS+ authentication feature could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator. This issue is due to incomplete validation of user-supplied input passed to an authentication script. An attacker could exploit this by injecting parameters into an authentication request, potentially allowing them to bypass authentication and log in as an administrator.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2021-04386
CVE-2021-34746
GHSA-GQX8-C4XR-C664

Affected Products

Cisco Enterprise Nfv Infrastructure