cisco enterprise-network-function-virtualization-infrastructure CVE-2019-1972 vulnerability in Cisco Products
Published on August 8, 2019

Cisco Enterprise NFV Infrastructure Software Privilege Escalation Vulnerability
A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow an authenticated, local attacker with valid administrator-level credentials to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient restrictions during the execution of an affected CLI command. An attacker could exploit this vulnerability by leveraging the insufficient restrictions during the execution of an affected command. A successful exploit could allow the attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root.

Vendor Advisory NVD

Weakness Type

Permissions, Privileges, and Access Controls

Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.


Products Associated with CVE-2019-1972

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-1972 are published in these products:

 
 

Affected Versions

Cisco Enterprise NFV Infrastructure Software:

Exploit Probability

EPSS
0.03%
Percentile
8.31%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.