Vulnerabilities > Cisco > Enterprise Network Function Virtualization Infrastructure > 3.5.1

DATE CVE VULNERABILITY TITLE RISK
2019-08-08 CVE-2019-1946 Improper Authentication vulnerability in Cisco Enterprise Network Function Virtualization Infrastructure
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management interface.
network
low complexity
cisco CWE-287
6.5
2019-08-07 CVE-2019-1895 Missing Authentication for Critical Function vulnerability in Cisco Enterprise Network Function Virtualization Infrastructure
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device.
network
low complexity
cisco CWE-306
critical
9.8