Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1894

Опубликовано: 06 июл. 2019
Источник: nvd
CVSS3: 7.2
CVSS2: 9
EPSS Низкий

Описание

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite or read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to improper input validation in NFVIS filesystem commands. An attacker could exploit this vulnerability by using crafted variables during the execution of an affected command. A successful exploit could allow the attacker to overwrite or read arbitrary files on the underlying OS.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:enterprise_nfv_infrastructure_software:3.9.1:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02549
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite or read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to improper input validation in NFVIS filesystem commands. An attacker could exploit this vulnerability by using crafted variables during the execution of an affected command. A successful exploit could allow the attacker to overwrite or read arbitrary files on the underlying OS.

CVSS3: 7.2
fstec
больше 6 лет назад

Уязвимость программного обеспечения инфраструктуры Cisco Enterprise NFV Infrastructure Software, связанная с неправильной проверкой входных данных в командах файловой системы NFVIS, позволяющая нарушителю читать или перезаписать произвольные файлы

EPSS

Процентиль: 85%
0.02549
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-20
CWE-20