File and Directory Information Exposure in Enterprise NFV Infrastructure Software - CVE-2019-12623

 

File and Directory Information Exposure in Enterprise NFV Infrastructure Software - CVE-2019-12623

Published: August 26, 2019


Vulnerability identifier: #VU20389
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12623
CWE-ID: CWE-538
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform file enumeration on an affected system.

The vulnerability exists in the web server functionality due to the web server responds with different error codes for exist and non-exist files. A remote attacker can send specially crafted GET requests for different file names and enumerate files residing on the system.

Affected software

Enterprise NFV Infrastructure Software

How to mitigate CVE-2019-12623

Install updates from vendor's website.

Enterprise NFV Infrastructure Software - update to 3.12.1

External References

Related Security Bulletins