CVE-2019-1971

Executive Summary

Cisco Enterprise NFV Infrastructure Software (NFVIS) web portal suffers from insufficient input validation, allowing unauthenticated remote attackers to inject commands during authentication and execute arbitrary code with root privileges on the underlying OS. This enables full system compromise without credentials.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2019-08-08T08:15:13.023 - Last Modified: 2026-08-24T18:22:58.150

Original Description: A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the web portal framework. An attacker could exploit this vulnerability by providing malicious input during web portal authentication. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.

"Difficulties are things that show a person what they are."

— Epictetus
Source: NVD