CVE-2019-1953
Executive Summary
Authenticated remote attacker can view the admin password in clear text due to logging during the first‑time password change in Cisco NFVIS web portal. Only the admin account during the initial reset is affected; subsequent changes are not logged. Exploitation requires a valid user credential and provides direct access to the system. No current CISA KEV listing.
Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2019-08-08T08:15:12.413 - Last Modified: 2026-08-24T18:22:58.150
Original Description: A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced to modify the default password when logging in to the web portal for the first time. Subsequent password changes are not logged and other accounts are not affected. An attacker could exploit this vulnerability by viewing the admin clear text password and using it to access the affected system. The attacker would need a valid user account to exploit this vulnerability.
"We must embrace pain and burn it as fuel for our journey."
— Kenji Miyazawa