CVE-2019-1952
Executive Summary
CVE-2019-1952 exposes a directory traversal flaw in Cisco NFVIS CLI that permits authenticated local administrators to read or overwrite arbitrary files on the device. The vulnerability stems from inadequate validation of command arguments, enabling attackers to manipulate file paths. Successful exploitation could compromise configuration files, system binaries, or sensitive data, potentially leading to full system compromise. No KEV listing yet.
Authoritative CVE Metadata - CVSS Base Score: 6.7 (MEDIUM) - Published: 2019-08-08T08:15:12.333 - Last Modified: 2026-08-24T18:22:58.150
Original Description: A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to overwrite or read arbitrary files. The attacker would need valid administrator privilege-level credentials. This vulnerability is due to improper input validation of CLI command arguments. An attacker could exploit this vulnerability by using directory traversal techniques when executing a vulnerable command. A successful exploit could allow the attacker to overwrite or read arbitrary files on an affected device.
"What matters is the value we've created in our lives, the people we've made happy and how much we've grown as people."
— Daisaku Ikeda