Improper input validation in Enterprise NFV Infrastructure Software - CVE-2018-0462
Published: September 6, 2018
Enterprise NFV Infrastructure Software
Detailed vulnerability description
The vulnerability allows a remote administrative attacker to cause DoS condition.
The vulnerability exists in the user management functionality of Cisco Enterprise NFV Infrastructure Software (NFVIS) due to insufficient validation of user-provided input. A remote attacker can log in with a highly privileged user account, perform a sequence of specific user management operations that interfere with the underlying operating system and permanently degrade the functionality of the affected system.