QID 317027
QID 317027: Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
A Vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator
Affected Products
Cisco Enterprise NFVIS Release 4.5.1 if the TACACS external authentication method is configured
QID Detection Logic (Unauthenticated):
A successful exploit could allow the attacker to bypass authentication and log in as an administrator to the affected device.
Solution
Customers are advised to refer to cisco-sa-nfvis-g2DMVVh for more information.
Vendor References
- cisco-sa-nfvis-g2DMVVh -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVh
CVEs related to QID 317027
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-nfvis-g2DMVVh |
|