CVE-2019-1960

MEDIUM

Cisco Enterprise NFV Infrastructure Software < 3.11.1 - Authenticated Arbitrary File Read

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1
Core References

Scores

CVSS v3 4.4
EPSS 0.0035
EPSS Percentile 27.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-78
Status published
Products (1)
cisco/enterprise_network_function_virtualization_infrastructure < 3.11.1
Published Aug 08, 2019
Tracked Since Feb 18, 2026