CVE-2019-1971
published 2019-08-08CVE-2019-1971: A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command…
PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.58%
88.1th percentile
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the web portal framework. An attacker could exploit this vulnerability by providing malicious input during web portal authentication. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_enterprise_nfv_infrastructure_software | >= unspecified < n/a | n/a |
| cisco | enterprise_network_function_virtualization_infrastructure | 3.6.2 – 3.8.1 | — |
| cisco | enterprise_nfv_infrastructure | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is unauthenticated command injection via the web portal authentication input fields of Cisco NFVIS — monitor for anomalous or shell-metacharacter-containing input in authentication requests to the NFVIS web portal ↗
- →Successful exploitation results in arbitrary command execution with root privileges on the underlying OS — alert on unexpected root-level process spawning from the NFVIS web portal service ↗
- →No authentication is required to exploit this vulnerability — any unauthenticated request to the NFVIS web portal with injection payloads should be treated as high-severity ↗
- ·No workarounds are available for this vulnerability — patching is the only mitigation ↗
- ·The vulnerability is rooted in insufficient input validation by the web portal framework itself, meaning WAF-style filtering of authentication inputs may reduce but not eliminate risk until patched ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Enterprise NFV Infrastructure Software Command Injection Vulnerability
vendor_cisco·2019-08-07·CVSS 8.1
CVE-2019-1971 [HIGH] CWE-78 Cisco Enterprise NFV Infrastructure Software Command Injection Vulnerability
Cisco Enterprise NFV Infrastructure Software Command Injection Vulnerability
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges.
The vulnerability is due to insufficient input validation by the web portal framework. An attacker could exploit this vulnerability by providing malicious input during web portal authentication. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/
Cisco
Cisco Enterprise NFV Infrastructure Software Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1971 Cisco Enterprise NFV Infrastructure Software Command Injection Vulnerability
CVE-2019-1971: Cisco Enterprise NFV Infrastructure Software Command Injection Vulnerability
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the web portal framework. An attacker could exploit this vulnerability by providing malicious input during web portal authentication. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. There are no
CVSS: 3.0
CWE: CWE-78, CWE-78
Bug IDs: CSCvm76628
GHSA
GHSA-9fqx-8qp3-fpv5: A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a
ghsa_unreviewed·2022-05-24
CVE-2019-1971 [CRITICAL] CWE-20 GHSA-9fqx-8qp3-fpv5: A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the web portal framework. An attacker could exploit this vulnerability by providing malicious input during web portal authentication. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-08
Published