cbcvebase.
CVE-2019-1971
published 2019-08-08

CVE-2019-1971: A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command…

PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.58%
88.1th percentile
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the web portal framework. An attacker could exploit this vulnerability by providing malicious input during web portal authentication. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscocisco_enterprise_nfv_infrastructure_software>= unspecified < n/an/a
ciscoenterprise_network_function_virtualization_infrastructure3.6.2 – 3.8.1
ciscoenterprise_nfv_infrastructure

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is unauthenticated command injection via the web portal authentication input fields of Cisco NFVIS — monitor for anomalous or shell-metacharacter-containing input in authentication requests to the NFVIS web portal
  • Successful exploitation results in arbitrary command execution with root privileges on the underlying OS — alert on unexpected root-level process spawning from the NFVIS web portal service
  • No authentication is required to exploit this vulnerability — any unauthenticated request to the NFVIS web portal with injection payloads should be treated as high-severity
  • ·No workarounds are available for this vulnerability — patching is the only mitigation
  • ·The vulnerability is rooted in insufficient input validation by the web portal framework itself, meaning WAF-style filtering of authentication inputs may reduce but not eliminate risk until patched

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.