Known vulnerabilities in Enterprise NFV Infrastructure Software

Software CPE: cpe:2.3:a:cisco_systems:enterprise_nfv_infrastructure_software:*:*:*:*:*:*:*:*
Total vulnerabilities: 33
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Enterprise NFV Infrastructure Software Enterprise NFV Infrastructure Software is affected by 33 known vulnerabilities: 4 high, 6 medium, 23 low Critical High Medium Low

Vulnerabilities (33)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU114565 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-20342
CWE-79 Low
No
No
4.18.1 29.08.2025 SB2025082977
#VU114490 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2025-20317
CWE-601 Medium
No
No
4.18.1 28.08.2025 SB2025082828
#VU88806 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-20295
CWE-78 Low
No
No
4.14.1 18.04.2024 SB2024041818
#VU88805 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-20356
CWE-78 Low
Available
No
4.14.1 18.04.2024 SB2024041816
#VU67956 - Improper Verification of Cryptographic Signature
CVE-2022-20929
CWE-347 High
No
No
4.9.1 06.10.2022 SB2022100618
#VU62816 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2022-20780
CWE-611 Medium
No
No
4.7.1 05.05.2022 SB2022050512
#VU62815 - Command injection
CVE-2022-20779
CWE-77 High
No
No
4.7.1 05.05.2022 SB2022050512
#VU62812 - Permissions, Privileges, and Access Controls
CVE-2022-20777
CWE-264 Medium
No
No
4.7.1 05.05.2022 SB2022050512
#VU59955 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-20655
CWE-78 Low
No
No
3.12.1 24.01.2022 SB2022012410
SB2022012512
#VU56260 - Improper Authentication
CVE-2021-34746
CWE-287 High
No
No
4.6.1 02.09.2021 SB2021090203
#VU52908 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-1421
CWE-78 Low
No
No
4.5.1 06.05.2021 SB2021050614
#VU49580 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-1127
CWE-79 Low
No
No
4.4.1 13.01.2021 SB2021011815
#VU46277 - Improper input validation
CVE-2020-3478
CWE-20 Medium
No
No
4.2.1 04.09.2020 SB2020090403
#VU46276 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-3365
CWE-22 Low
No
No
4.2.1 04.09.2020 SB2020090403
#VU29214 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-3236
CWE-22 Low
No
No
4.1.1 23.06.2020 SB2020062318
#VU25475 - Improper Verification of Cryptographic Signature
CVE-2020-3138
CWE-347 Low
No
No
- 20.02.2020 SB2020022005
#VU20389 - File And Directory Information Exposure
CVE-2019-12623
CWE-538 Low
No
No
3.12.1 26.08.2019 SB2019082607
#VU20383 - Improper input validation
CVE-2019-1984
CWE-20 Low
No
No
3.12.1 23.08.2019 SB2019082607
#VU20328 - Improper input validation
CVE-2019-1960
CWE-20 Low
No
No
3.11.1 20.08.2019 SB2019080833
#VU20327 - Improper input validation
CVE-2019-1959
CWE-20 Low
No
No
3.11.1 20.08.2019 SB2019080832


Showing elements 1 - 20 out of 33