Information disclosure in Enterprise NFV Infrastructure Software - CVE-2018-0460
Published: September 5, 2018 / Updated: September 6, 2018
Enterprise NFV Infrastructure Software
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The vulnerability exists in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) due to insufficient authorization and parameter validation checks. A remote attacker can send a malicious API request with the authentication credentials of a low-privileged user and read any file on the affected system.