CVE-2019-1588

MEDIUM

Cisco NX-OS < 14.0(1h) - Authenticated Arbitrary File Read

Title source: llm
STIX 2.1

Description

A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms of user-supplied input sent to an affected device. A successful exploit could allow the attacker unauthorized access to read arbitrary files on an affected device. This vulnerability has been fixed in version 14.0(1h).

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107316

Scores

CVSS v3 4.4
EPSS 0.0034
EPSS Percentile 26.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-269
Status published
Products (1)
cisco/nx-os < 14.0\(1h\)
Published Mar 06, 2019
Tracked Since Feb 18, 2026