#VU12783 Command injection in Enterprise NFV Infrastructure Software - CVE-2018-0324
Published: May 17, 2018
Enterprise NFV Infrastructure Software
Cisco Systems, Inc
Description
The vulnerability allows a local authenticated attacker to execute arbitrary commands on the target system.
The weakness exists in the CLI parser due to insufficient input validation of command parameters. A local attacker can invoke a vulnerable CLI command with specially crafted parameters and execute arbitrary commands with a non-root user account on the underlying Linux operating system.