---
id: CVE-2020-3236
title: >-
  A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software
  (NFVIS) could allow an authenticated, local attacker to gain root shell access
  to the underlying operating system and overwrite or read arbitrary files
summary: >-
  A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software
  (NFVIS) could allow an authenticated, local attacker to gain root shell access
  to the underlying operating system and overwrite or read arbitrary files. The
  attac…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-22
vendor: cisco
product: enterprise_nfv_infrastructure_software
affected:
  - enterprise_nfv_infrastructure_software < 4.1.1
patched:
  - enterprise_nfv_infrastructure_software 4.1.1
published: '2020-06-18'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-3236'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-ptrav-SHMzzwVR
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-ptrav-SHMzzwVR
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00466
epssPercentile: 0.39405
ingestedAt: '2026-08-24T19:09:59.556Z'
---

## Overview

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files. The attacker would need valid administrative credentials. This vulnerability is due to improper input validation of CLI command arguments. An attacker could exploit this vulnerability by using path traversal techniques when executing a vulnerable command. A successful exploit could allow the attacker to gain root shell access to the underlying operating system and overwrite or read arbitrary files on an affected device.

## Affected

- `enterprise_nfv_infrastructure_software < 4.1.1`

## Remediation

Upgrade past the affected range:

- `enterprise_nfv_infrastructure_software 4.1.1`
