CVE-2019-1959: Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1959?
CVE-2019-1959 is rated as a medium severity vulnerability.
How do I fix CVE-2019-1959?
To fix CVE-2019-1959, update to Cisco Enterprise Network Functions Virtualization Infrastructure Software version 3.11.1 or later.
Who is affected by CVE-2019-1959?
CVE-2019-1959 affects Cisco Enterprise Network Functions Virtualization Infrastructure Software versions prior to 3.11.1.
What type of attacker can exploit CVE-2019-1959?
An authenticated, local attacker can exploit CVE-2019-1959 to read arbitrary files on the operating system.
What are the potential impacts of CVE-2019-1959?
The potential impacts of CVE-2019-1959 include unauthorized access to sensitive files on the affected device's operating system.