EXPOSURES › CVE-2019-1971
CVE-2019-1971
CRITICAL
DETAIL
SourceNVD · cve
Published2019-08-08
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-1971 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
DESCRIPTION
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the web portal framework. An attacker could exploit this vulnerability by providing malicious input during web portal authentication. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.60
Criticism for severe root-privilege command injection flaw in enterprise NFV infrastructure, though no direct press condemnation found in provided sources.
Severe technical flaw allowing root command execution
"execute arbitrary commands with root privileges on the underlying operating system."
Criticism of severity scoring methodology
"Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5."
Neutral CISA KEV catalog
Neutral vulnerability database
Neutral vulnerability reference site
Neutral breach tracker
AFFECTED FEDRAMP PRODUCTS · 7
| PRODUCT | STATUS |
|---|---|
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |