---
id: CVE-2019-1952
title: >-
  A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software
  (NFVIS) could allow an authenticated, local attacker to overwrite or read
  arbitrary files
summary: >-
  A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software
  (NFVIS) could allow an authenticated, local attacker to overwrite or read
  arbitrary files. The attacker would need valid administrator privilege-level
  credentials…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-20
vendor: cisco
product: enterprise_nfv_infrastructure_software
affected:
  - enterprise_nfv_infrastructure_software < 3.10.1
patched:
  - enterprise_nfv_infrastructure_software 3.10.1
published: '2019-08-08'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-1952'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190807-nfv-cli-path
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190807-nfv-cli-path
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00716
epssPercentile: 0.52334
ingestedAt: '2026-08-24T19:09:59.211Z'
---

## Overview

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to overwrite or read arbitrary files. The attacker would need valid administrator privilege-level credentials. This vulnerability is due to improper input validation of CLI command arguments. An attacker could exploit this vulnerability by using directory traversal techniques when executing a vulnerable command. A successful exploit could allow the attacker to overwrite or read arbitrary files on an affected device.

## Affected

- `enterprise_nfv_infrastructure_software < 3.10.1`

## Remediation

Upgrade past the affected range:

- `enterprise_nfv_infrastructure_software 3.10.1`
