CVE-2019-1960: Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1960?
CVE-2019-1960 has a medium severity rating due to the potential for an authenticated attacker to read arbitrary files on the operating system.
How do I fix CVE-2019-1960?
To mitigate CVE-2019-1960, users should upgrade their Cisco Enterprise NFV Infrastructure Software to version 3.11.1 or later.
What type of attacker can exploit CVE-2019-1960?
An authenticated, local attacker can exploit CVE-2019-1960 to access sensitive files on the underlying OS.
Which Cisco products are affected by CVE-2019-1960?
CVE-2019-1960 affects Cisco Enterprise Network Function Virtualization Infrastructure Software versions below 3.11.1.
What can an attacker achieve by exploiting CVE-2019-1960?
By exploiting CVE-2019-1960, an attacker can read arbitrary files on the underlying operating system, potentially compromising sensitive data.