---
id: CVE-2020-3365
title: >-
  A vulnerability in the directory permissions of Cisco Enterprise NFV
  Infrastructure Software (NFVIS) could allow an authenticated, remote attacker
  to perform a directory traversal attack on a limited set of restricted
  directories
summary: >-
  A vulnerability in the directory permissions of Cisco Enterprise NFV
  Infrastructure Software (NFVIS) could allow an authenticated, remote attacker
  to perform a directory traversal attack on a limited set of restricted
  directories. The vu…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-22
  - CWE-22
vendor: cisco
product: enterprise_nfv_infrastructure_software
affected:
  - 'enterprise_nfv_infrastructure_software >= 3.5.1, <= 4.1.2'
published: '2020-09-04'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-3365'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-path-emy79OC2
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-path-emy79OC2
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01612
epssPercentile: 0.74484
ingestedAt: '2026-08-24T19:09:59.626Z'
---

## Overview

A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories. The vulnerability is due to a flaw in the logic that governs directory permissions. An attacker could exploit this vulnerability by using capabilities that are not controlled by the role-based access control (RBAC) mechanisms of the software. A successful exploit could allow the attacker to overwrite files on an affected device.

## Affected

- `enterprise_nfv_infrastructure_software >= 3.5.1, <= 4.1.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
