Severity
4.4MEDIUM
EPSS
0.1%
top 69.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8
Latest updateMay 24

Description

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-xxqf-p783-9fhr: Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files2022-05-24
CVEList
Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities2019-08-08

📋Vendor Advisories

1
Cisco
Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities2019-08-07

💬Community

1
Bugzilla
CVE-2019-10210 postgresql: Windows installer writes superuser password to unprotected temporary file2019-07-30
CVE-2019-1960 (MEDIUM CVSS 4.4) | Multiple vulnerabilities in Cisco E | cvebase.io