---
id: CVE-2019-1960
title: >-
  Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software
  (NFVIS) could allow an authenticated, local attacker to read arbitrary files
  on the underlying operating system (OS) of an affected device
summary: >-
  Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software
  (NFVIS) could allow an authenticated, local attacker to read arbitrary files
  on the underlying operating system (OS) of an affected device. For more
  information abo…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-20
  - CWE-78
vendor: cisco
product: enterprise_nfv_infrastructure_software
affected:
  - enterprise_nfv_infrastructure_software < 3.11.1
patched:
  - enterprise_nfv_infrastructure_software 3.11.1
published: '2019-08-08'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-1960'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190807-nfv-read
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190807-nfv-read
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00351
epssPercentile: 0.28847
ingestedAt: '2026-08-24T19:09:59.326Z'
---

## Overview

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

## Affected

- `enterprise_nfv_infrastructure_software < 3.11.1`

## Remediation

Upgrade past the affected range:

- `enterprise_nfv_infrastructure_software 3.11.1`
