Improper input validation in Enterprise NFV Infrastructure Software - CVE-2018-0459
Published: September 6, 2018
Enterprise NFV Infrastructure Software
Detailed vulnerability description
The vulnerability allows a remote administrative attacker to cause DoS condition.
The vulnerability exists in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) due to insufficient server-side authorization checks. A remote attacker who is logged in to the web-based management interface as a low-privileged user can send a specially crafted HTTP request and use the low-privileged user account to reboot or shut down the affected system.