CVE-2018-0460

CVE-2018-0460: Cisco Enterprise NFV Infrastructure Software Information Disclosure Vulnerability

Vendor Cisco
Product Cisco Enterprise NFV Infrastructure Software
Weakness CWE-285
Published October 5, 2018
Last update November 26, 2024

CVSS base score

What the vulnerability does

01Description

A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parameter validation checks. An attacker could exploit this vulnerability by sending a malicious API request with the authentication credentials of a low-privileged user. A successful exploit could allow the attacker to read any file on the affected system.

Key dates

02Disclosure timeline

October 5, 2018 CVE published
November 26, 2024 Record updated