Skip to main content

Critical bugs found in Cisco Enterprise NFV software

posted onMay 4, 2022
by l33tdawg
Reuters
Credit: Reuters

Administrators need to patch their Cisco Enterprise Network Function Virtualisation Infrastructure Software (NFVIS) to address several critical flaws, rated as 9.9 out of 10 on the Common Vulnerabilities Scoring System (CVSS).

In its advisory, Cisco said the vulnerabilities could allow an attacker to escape from guest virtual machines to the host server. Attackers could also inject commands as the root superuser, and leak system data from the host server to the virtual machine.

The Linux-based NFVIS is used by service providers and enterprises to design, deploy and manage virtualised network functions, such as routing, firewalls and wide area network accelerators. Insufficient guest restrictions let attackers send API calls from a VM, with root privileges, to fully compromise host systems, Cisco warned. A second bug in the image registration process of NFVIS allows unauthenticated, remote attackers to inject commands, again as root with full system access.

Source

Tags

Security

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th