---
id: CVE-2020-3138
title: >-
  A vulnerability in the upgrade component of Cisco Enterprise NFV
  Infrastructure Software (NFVIS) could allow an authenticated, local attacker
  to install a malicious file when upgrading
summary: >-
  A vulnerability in the upgrade component of Cisco Enterprise NFV
  Infrastructure Software (NFVIS) could allow an authenticated, local attacker
  to install a malicious file when upgrading. The vulnerability is due to
  insufficient signature …
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-347
  - CWE-347
vendor: cisco
product: enterprise_nfv_infrastructure_software
affected:
  - enterprise_nfv_infrastructure_software <= 3.11.1
published: '2020-02-19'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-3138'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-codex-shs4NhvS
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-codex-shs4NhvS
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00207
epssPercentile: 0.11172
ingestedAt: '2026-08-24T19:09:59.517Z'
---

## Overview

A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature validation. An attacker could exploit this vulnerability by providing a crafted upgrade file. A successful exploit could allow the attacker to upload crafted code to the affected device.

## Affected

- `enterprise_nfv_infrastructure_software <= 3.11.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
