Cisco Releases Critical Security Update for Enterprise NFV Infrastructure Software Vulnerabilities
Scheduled update addresses one critical and two high impact vulnerabilities
Summary
Scheduled update addresses one critical and two high impact vulnerabilities
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco has released a security update to address one critical and two high impact vulnerabilities in Cisco Enterprise NFV Infrastructure Software.
These vulnerabilities could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. A remote, unauthenticated attacker could exploit some of these vulnerabilities to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review Cisco Security Advisories and cisco-sa-NFVIS-MUL-7DySRX9, and apply the necessary updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 6 May 2022 3:05 pm