Improper input validation in Enterprise NFV Infrastructure Software - CVE-2019-1656

 

Improper input validation in Enterprise NFV Infrastructure Software - CVE-2019-1656

Published: January 23, 2019 / Updated: January 24, 2019


Vulnerability identifier: #VU17202
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1656
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass security restrictions.

The vulnerability exists due to improper input validation. A local attacker can send specially crafted commands and gain shell access with a non-root user account to the underlying Linux operating system on the affected device and potentially access system configuration files with sensitive information.


Affected software

Enterprise NFV Infrastructure Software

How to mitigate CVE-2019-1656

Install update from vendor's website.


External References

Related Security Bulletins