CVE-2019-1656

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation in the affected software. An attacker could exploit this vulnerability by sending crafted commands to the affected device. An exploit could allow the attacker to gain shell access with a nonroot user account to the underlying Linux operating system on the affected device and potentially access system configuration files with sensitive information. This vulnerability only affects console connections from CIMC. It does not apply to remote connections, such as telnet or SSH.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:enterprise_nfv_infrastructure_software:3.9.1:*:*:*:*:*:*:*

History

21 Nov 2024, 04:37

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/106715 - Third Party Advisory () http://www.securityfocus.com/bid/106715 - Third Party Advisory
References () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-nfvis-shell-access - Vendor Advisory () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-nfvis-shell-access - Vendor Advisory

Information

Published : 2019-01-24 16:29

Updated : 2024-11-21 04:37


NVD link : CVE-2019-1656

Mitre link : CVE-2019-1656

CVE.ORG link : CVE-2019-1656


JSON object : View

Products Affected

cisco

  • enterprise_nfv_infrastructure_software
CWE
CWE-20

Improper Input Validation