#VU12782 Path traversal in Enterprise NFV Infrastructure Software - CVE-2018-0323
Published: May 17, 2018 / Updated: May 17, 2018
Enterprise NFV Infrastructure Software
Cisco Systems, Inc
Description
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information on the target system.
The weakness exists in the web management interface due to insufficient validation of web request parameters. A remote attacker who has access to the web management interface can send a specially crafted web request, trigger path traversal and gain access to potentially sensitive information.