{"containers":{"cna":{"affected":[{"product":"Cisco Enterprise NFV Infrastructure Software","vendor":"Cisco","versions":[{"lessThan":"n/a","status":"affected","version":"unspecified","versionType":"custom"}]}],"datePublic":"2019-08-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory."}],"exploits":[{"lang":"en","value":"The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."}],"metrics":[{"cvssV3_0":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.0"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-20","description":"CWE-20","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2019-08-08T07:35:49.000Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"name":"20190807 Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities","tags":["vendor-advisory","x_refsource_CISCO"],"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190807-nfv-read"}],"source":{"advisory":"cisco-sa-20190807-nfv-read","defect":[["CSCvm76669","CSCvn12428"]],"discovery":"INTERNAL"},"title":"Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities","x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@cisco.com","DATE_PUBLIC":"2019-08-07T16:00:00-0700","ID":"CVE-2019-1959","STATE":"PUBLIC","TITLE":"Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Cisco Enterprise NFV Infrastructure Software","version":{"version_data":[{"affected":"<","version_affected":"<","version_value":"n/a"}]}}]},"vendor_name":"Cisco"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory."}]},"exploit":[{"lang":"en","value":"The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."}],"impact":{"cvss":{"baseScore":"4.4","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20"}]}]},"references":{"reference_data":[{"name":"20190807 Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities","refsource":"CISCO","url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190807-nfv-read"}]},"source":{"advisory":"cisco-sa-20190807-nfv-read","defect":[["CSCvm76669","CSCvn12428"]],"discovery":"INTERNAL"}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T18:35:52.368Z"},"title":"CVE Program Container","references":[{"name":"20190807 Cisco Enterprise NFV Infrastructure Software Arbitrary File Read Vulnerabilities","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190807-nfv-read"}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-11-21T18:57:21.882213Z","id":"CVE-2019-1959","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-21T19:16:33.730Z"}}]},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2019-1959","datePublished":"2019-08-08T07:35:49.071Z","dateReserved":"2018-12-06T00:00:00.000Z","dateUpdated":"2024-11-21T19:16:33.730Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}