VYPR
Unrated severityNVD Advisory· Published May 4, 2022· Updated Nov 6, 2024

Cisco Enterprise NFV Infrastructure Software Vulnerabilities

CVE-2022-20777

Description

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2022-20777 allows a VM with a crafted IP address (192.168.10.12) to access internal host APIs, leading to root command injection on the host.

Vulnerability

CVE-2022-20777 is an improper access control vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) versions up to 4.5.1-FC2 [2]. The NGIO (Next Generation I/O) network interface, intended for communication between trusted Cisco VMs and the host, has an overly permissive firewall rule that accepts any IP traffic from 192.168.10.12 [2]. This address can be assigned to a non-Cisco VM [2].

Exploitation

An attacker with the ability to configure a virtual machine (VM) on the NFVIS system can assign it the IP address 192.168.10.12 and attach it to a network that includes the int-mgmt-net subnet (192.168.10.0/25) [2]. The attacker then connects to the host's internal API on 192.168.10.1:8000 and injects shell metacharacters into the vcpu parameter, achieving root command injection [2]. A separate proof-of-concept (PoC #2) shows that from a Cisco ISRv VM with NGIO enabled, a similar command injection via curl can also achieve root execution [2].

Impact

Successful exploitation results in an attacker escaping from the guest VM to the host machine and executing arbitrary commands as root [2]. This leads to full compromise of the host, including potential data leakage and further attacks against other VMs or infrastructure.

Mitigation

Cisco has released NFVIS version 4.7.1 which contains the security patch for this vulnerability [1][2]. Users should upgrade to this fixed version. As a workaround, administrators are advised to restrict exposure of TCP ports used by Cisco agents, use separate VRF (network namespaces) for NGIO interfacing, and enable mutual SSL authentication with Cisco components [2].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.