PT-2019-3077 · Cisco · Cisco Enterprise Nfv Infrastructure

Published

2019-08-07

·

Updated

2020-10-16

·

CVE-2019-1972

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Enterprise NFV Infrastructure Software (NFVIS) (affected versions not specified)
Description The issue is related to insufficient restrictions during the execution of an affected CLI command, allowing an authenticated, local attacker with valid administrator-level credentials to elevate privileges and execute arbitrary commands on the underlying operating system as root. An attacker could exploit this by leveraging the insufficient restrictions during the execution of an affected command.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03059
CVE-2019-1972

Affected Products

Cisco Enterprise Nfv Infrastructure