Vulnerabilities > Cisco > Enterprise Network Function Virtualization Infrastructure > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-08-08 CVE-2019-1971 Improper Input Validation vulnerability in Cisco Enterprise Network Function Virtualization Infrastructure
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges.
network
low complexity
cisco CWE-20
critical
9.8
2019-08-07 CVE-2019-1895 Missing Authentication for Critical Function vulnerability in Cisco Enterprise Network Function Virtualization Infrastructure
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device.
network
low complexity
cisco CWE-306
critical
9.8