CVE-2019-12623
Summary
| CVE | CVE-2019-12623 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-21 18:15:00 UTC |
| Updated | 2019-10-09 23:45:00 UTC |
| Description | A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affected system. The vulnerability is due to the web server responding with different error codes for existing and non-existing files. An attacker could exploit this vulnerability by sending GET requests for different file names. A successful exploit could allow the attacker to enumerate files residing on the system. |
Risk And Classification
Problem Types: CWE-538
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Enterprise Network Functions Virtualization Infrastructure | All | All | All | All |
| Application | Cisco | Enterprise Network Functions Virtualization Infrastructure | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Enterprise Network Functions Virtualization Infrastructure Software File Enumeration Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.