Thursday, July 4, 2019

Vuln: Cisco Enterprise NFV Infrastructure Software CVE-2019-1894 Arbitrary File Overwrite Vulnerability



Cisco Enterprise NFV Infrastructure Software is prone to an arbitrary file-overwrite vulnerability.

Successful exploits may allow an attacker to overwrite or read arbitrary files on the underlying OS.

This issue is being tracked by Cisco Bug ID CSCvn12407.
exploit



Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.com.
solution



Solution:
Updates are available. Please see the references or vendor advisory for more information.

info



Bugtraq ID: 109037
Class: Input Validation Error
CVE: CVE-2019-1894
Remote: Yes
Local: No
Published: Jul 03 2019 12:00AM
Updated: Jul 03 2019 12:00AM
Credit: Cisco.
Vulnerable: Cisco Enterprise NFV Infrastructure Software (NFVIS) 3.9.2
Cisco Enterprise NFV Infrastructure Software (NFVIS) 3.9.1
Cisco Enterprise NFV Infrastructure Software (NFVIS) 3.8.1
Cisco Enterprise NFV Infrastructure Software (NFVIS) 3.7.1
Cisco Enterprise NFV Infrastructure Software (NFVIS) 3.6.3
Not Vulnerable: Cisco Enterprise NFV Infrastructure Software (NFVIS) 3.10.1
references



from SecurityFocus Vulnerabilities https://ift.tt/2Xo2IRy

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.