Cisco Enterprise Nfv Infrastructure Software vulnerabilities
41 known vulnerabilities affecting cisco/cisco_enterprise_nfv_infrastructure_software.
Total CVEs
41
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH10MEDIUM26
Vulnerabilities
Page 2 of 3
CVE-2019-1984MEDIUMCVSS 6.5≥ unspecified, < 3.12.12019-08-21
CVE-2019-1984 [MEDIUM] CWE-20 CVE-2019-1984: A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS)
A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. The vulnerability is due to improper input validation in an NFVIS file-system command. An attac
cvelistv5nvd
CVE-2019-1971CRITICALCVSS 9.8≥ unspecified, < n/a2019-08-08
CVE-2019-1971 [CRITICAL] CWE-78 CVE-2019-1971: A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allo
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the web portal framework. An attacker could exploit this vulne
cvelistv5nvd
CVE-2019-1973MEDIUMCVSS 4.8≥ unspecified, < n/a2019-08-08
CVE-2019-1973 [MEDIUM] CWE-79 CVE-2019-1973: A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS)
A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to improper input validation of log file content stored on the affected device. An attacker co
cvelistv5nvd
CVE-2019-1946MEDIUMCVSS 6.5≥ unspecified, < 3.10.12019-08-08
CVE-2019-1946 [MEDIUM] CWE-287 CVE-2019-1946: A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Softwar
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management interface. The vulnerability is due to an incorrect implementation of authentication in the web-based management interf
cvelistv5nvd
CVE-2019-1952MEDIUMCVSS 6.7≥ unspecified, < 3.10.12019-08-08
CVE-2019-1952 [MEDIUM] CWE-22 CVE-2019-1952: A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an au
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to overwrite or read arbitrary files. The attacker would need valid administrator privilege-level credentials. This vulnerability is due to improper input validation of CLI command arguments. An attacker could exploit this vul
cvelistv5nvd
CVE-2019-1960MEDIUMCVSS 4.4≥ unspecified, < n/a2019-08-08
CVE-2019-1960 [MEDIUM] CWE-20 CVE-2019-1960: Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an auth
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2019-1953MEDIUMCVSS 6.5≥ unspecified, < 3.9.12019-08-08
CVE-2019-1953 [MEDIUM] CWE-532 CVE-2019-1953: A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allo
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced to modify the default password when logging in to the web portal for the first time. Subsequen
cvelistv5nvd
CVE-2019-1961MEDIUMCVSS 4.9≥ unspecified, < n/a2019-08-08
CVE-2019-1961 [MEDIUM] CWE-532 CVE-2019-1961: A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to the improper input validation of tar packages uploaded through the Web Portal to the Image Repository. An attacker could
cvelistv5nvd
CVE-2019-1959MEDIUMCVSS 4.4≥ unspecified, < n/a2019-08-08
CVE-2019-1959 [MEDIUM] CWE-20 CVE-2019-1959: Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an auth
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2019-1972MEDIUMCVSS 6.7≥ unspecified, < n/a2019-08-08
CVE-2019-1972 [MEDIUM] CWE-264 CVE-2019-1972: A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow
A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow an authenticated, local attacker with valid administrator-level credentials to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient restrictions during the execution of an
cvelistv5nvd
CVE-2019-1895CRITICALCVSS 9.8≥ unspecified, < 3.12.12019-08-07
CVE-2019-1895 [CRITICAL] CWE-306 CVE-2019-1895: A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NF
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient authentication mechanism used to establish
cvelistv5nvd
CVE-2019-1893HIGHCVSS 7.8≥ unspecified, < 3.10.12019-07-06
CVE-2019-1893 [HIGH] CWE-77 CVE-2019-1893: A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device as root. The vulnerability is due to insufficient input validation of a configuration file that is accessible to a local shell user. An attacker co
cvelistv5nvd
CVE-2019-1894HIGHCVSS 7.2≥ unspecified, < 3.10.12019-07-06
CVE-2019-1894 [HIGH] CWE-20 CVE-2019-1894: A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite or read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to improper input validation in NFVIS filesystem commands. An attacker could exploi
cvelistv5nvd
CVE-2019-1656MEDIUMCVSS 5.3vn/a2019-01-24
CVE-2019-1656 [MEDIUM] CWE-20 CVE-2019-1656: A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an au
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation in the affected software. An attacker could exploit this vulnerability by sending craft
cvelistv5nvd
CVE-2018-15402HIGHCVSS 8.8vn/a2018-10-17
CVE-2018-15402 [HIGH] CWE-352 CVE-2018-15402: A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticat
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks. The vulnerability is due to improper validation of Origin headers on HTTP requests within the management interface. An attacker could exploit this vulnerability by convincing a ta
cvelistv5nvd
CVE-2018-0460MEDIUMCVSS 6.5vn/a2018-10-05
CVE-2018-0460 [MEDIUM] CWE-285 CVE-2018-0460: A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parameter validation checks. An attacker could exploit this vulnerability by sending a malicious API request with the aut
cvelistv5nvd
CVE-2018-0462MEDIUMCVSS 4.9vn/a2018-10-05
CVE-2018-0462 [MEDIUM] CWE-20 CVE-2018-0462: A vulnerability in the user management functionality of Cisco Enterprise NFV Infrastructure Software
A vulnerability in the user management functionality of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a denial of service (DoS) attack against an affected system. The vulnerability is due to insufficient validation of user-provided input. An attacker could exploit this vulnerability by log
cvelistv5nvd
CVE-2018-0459MEDIUMCVSS 6.5vn/a2018-10-05
CVE-2018-0459 [MEDIUM] CWE-285 CVE-2018-0459: A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Softwar
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerability is due to insufficient server-side authorization checks. An attacker who is logged in to the web-based management interface as
cvelistv5nvd
CVE-2018-0279HIGHCVSS 8.8vCisco Enterprise NFV Infrastructure Software2018-05-17
CVE-2018-0279 [HIGH] CWE-20 CVE-2018-0279: A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation of comman
cvelistv5
CVE-2018-0324MEDIUMCVSS 6.7vCisco Enterprise NFV Infrastructure Software2018-05-17
CVE-2018-0324 [MEDIUM] CWE-77 CVE-2018-0324: A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to pe
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters in the CLI parser. An attacker could exp
cvelistv5