CVE-2019-1656 (CNNVD-201901-873)
中文标题:
Cisco Enterprise NFV Infrastructure Software 输入验证漏洞
英文标题:
Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability
漏洞描述
中文描述:
Cisco Enterprise NFV Infrastructure Software(NFVIS)是美国思科(Cisco)公司的一套NVF基础架构软件平台。该平台可以通过中央协调器和控制器实现虚拟化服务的全生命周期管理。 Cisco Enterprise NFVIS中的CLI存在输入验证漏洞。本地攻击者可通过发送特制的命令利用该漏洞访问底层Linux操作系统的shell。
英文描述:
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation in the affected software. An attacker could exploit this vulnerability by sending crafted commands to the affected device. An exploit could allow the attacker to gain shell access with a nonroot user account to the underlying Linux operating system on the affected device and potentially access system configuration files with sensitive information. This vulnerability only affects console connections from CIMC. It does not apply to remote connections, such as telnet or SSH.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Enterprise NFV Infrastructure Software | n/a | - | - |
cpe:2.3:a:cisco:cisco_enterprise_nfv_infrastructure_software:n_a:*:*:*:*:*:*:*
|
| cisco | enterprise_nfv_infrastructure_software | 3.9.1 | - | - |
cpe:2.3:a:cisco:enterprise_nfv_infrastructure_software:3.9.1:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-1656 |
2025-11-11 15:20:08 | 2025-11-11 07:35:37 |
| NVD | nvd_CVE-2019-1656 |
2025-11-11 14:56:20 | 2025-11-11 07:44:08 |
| CNNVD | cnnvd_CNNVD-201901-873 |
2025-11-11 15:10:09 | 2025-11-11 07:54:18 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 输入验证错误
- cnnvd_id: 未提取 -> CNNVD-201901-873
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']