---
id: CVE-2019-1946
title: >-
  A vulnerability in the web-based management interface of Cisco Enterprise NFV
  Infrastructure Software (NFVIS) could allow an unauthenticated, remote
  attacker to bypass authentication and get limited access to the web-based
  management int…
summary: >-
  A vulnerability in the web-based management interface of Cisco Enterprise NFV
  Infrastructure Software (NFVIS) could allow an unauthenticated, remote
  attacker to bypass authentication and get limited access to the web-based
  management int…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-287
  - CWE-287
vendor: cisco
product: enterprise_nfv_infrastructure_software
affected:
  - enterprise_nfv_infrastructure_software < 3.10.1
patched:
  - enterprise_nfv_infrastructure_software 3.10.1
published: '2019-08-08'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-1946'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190807-nfvis-authbypass
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190807-nfvis-authbypass
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01443
epssPercentile: 0.71657
ingestedAt: '2026-08-24T19:09:59.171Z'
---

## Overview

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management interface. The vulnerability is due to an incorrect implementation of authentication in the web-based management interface. An attacker could exploit this vulnerability by sending a crafted authentication request to the web-based management interface on an affected system. A successful exploit could allow the attacker to view limited configuration details and potentially upload a virtual machine image.

## Affected

- `enterprise_nfv_infrastructure_software < 3.10.1`

## Remediation

Upgrade past the affected range:

- `enterprise_nfv_infrastructure_software 3.10.1`
