CVE-2019-1588: Cisco Nexus 9000 Series Fabric Switches Application-Centric Infrastructure Mode Arbitrary File Read Vulnerability
A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-1588?
CVE-2019-1588 is a vulnerability in the Cisco Nexus 9000 Series Fabric Switches that allows an authenticated, local attacker to read arbitrary files on the device.
What is the severity of CVE-2019-1588?
CVE-2019-1588 has a severity value of 4.4, which is considered medium.
How does CVE-2019-1588 affect Cisco Nexus 9000 switches running in ACI mode?
CVE-2019-1588 affects Cisco Nexus 9000 switches running in ACI mode by allowing an authenticated, local attacker to read arbitrary files on the affected device.
How can I fix CVE-2019-1588?
To fix CVE-2019-1588, it is recommended to apply the necessary updates or patches provided by Cisco.
Is Cisco aware of CVE-2019-1588?
Yes, Cisco is aware of CVE-2019-1588 and has released a security advisory regarding this vulnerability.