Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1588

Опубликовано: 06 мар. 2019
Источник: nvd
CVSS3: 4.4
CVSS3: 4.4
CVSS2: 2.1
EPSS Низкий

Описание

A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:*
Версия до 14.0\(1h\) (исключая)
cpe:2.3:h:cisco:nexus_9000:-:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00183
Низкий

4.4 Medium

CVSS3

4.4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-20
CWE-269

Связанные уязвимости

CVSS3: 4.4
github
больше 3 лет назад

A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).

CVSS3: 4.4
fstec
больше 6 лет назад

Уязвимость средства управления информационной инфраструктурой Cisco Application Policy Infrastructure Controller, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю осуществить чтение произвольного файла

EPSS

Процентиль: 40%
0.00183
Низкий

4.4 Medium

CVSS3

4.4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-20
CWE-269