CVE-2019-15958
published 2019-11-26CVE-2019-15958: A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote…
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.29%
87.0th percentile
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA) configuration and registration process of an affected device. An attacker could exploit this vulnerability by uploading a malicious file during the HA registration period. A successful exploit could allow the attacker to execute arbitrary code with root-level privileges on the underlying operating system. Note: This vulnerability can only be exploited during the HA registration period. See the Details section for more information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_prime_infrastructure | >= unspecified < n/a | n/a |
| cisco | evolved_programmable_network_manager | < 3.0.2 | 3.0.2 |
| cisco | prime_infrastructure | < 3.4.2 | 3.4.2 |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | >= 3.5 < 3.5.1 | 3.5.1 |
| cisco | prime_infrastructure_and_evolved_programmable_network_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector targets the REST API endpoint used during High Availability (HA) configuration and registration; monitor for unauthenticated file upload requests to the HA REST API on affected Cisco PI/EPNM devices ↗
- →Attack is only possible during the HA registration/pairing window; alert on unexpected file uploads to the HA REST API outside of planned maintenance windows ↗
- →Both the active and standby HA nodes are attack surfaces; ensure monitoring covers both nodes for anomalous REST API activity ↗
- →Successful exploitation results in root-level code execution on the underlying OS; monitor for unexpected privileged process spawning from the PI/EPNM application process ↗
- →Track Cisco Bug IDs CSCvp79419 and CSCvp79611 for patch status verification on deployed Cisco PI and EPNM instances ↗
- ·The vulnerability is only exploitable when the High Availability feature is enabled and the device is actively in the HA registration/pairing period; devices not using HA or outside the registration window are not directly exploitable ↗
- ·No workarounds are available; remediation requires applying Cisco-released software updates ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4gj6-pp76-wxr5: A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticate
ghsa_unreviewed·2022-05-24
CVE-2019-15958 [HIGH] CWE-20 GHSA-4gj6-pp76-wxr5: A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticate
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA) configuration and registration process of an affected device. An attacker could exploit this vulnerability by uploading a malicious file during the HA registration period. A successful exploit could allow the attacker to execute arbitrary code with root-level privileges on the underlying operating system. Note: This vulnerability can only be exploited during the HA registration period. See the Details section for more information.
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
vendor_cisco·2019-11-06·CVSS 9.8
CVE-2019-15958 [CRITICAL] CWE-20 Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system.
The vulnerability exists because affected devices with the High Availability (HA) feature enabled do not properly perform input validation. An attacker could exploit this vulnerability by uploading a malicious file to either the HA active or standby device. A successful exploit could allow the attacker to execute arbitrary code with root-level privileges on the underlying operating system.
Cisco has released software updates that address th
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-15958 Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
CVE-2019-15958: Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability exists because affected devices with the High Availability (HA) feature enabled do not properly perform input validation. An attacker could exploit this vulnerability by uploading a malicious file to either the HA active or standby device. A successful exploit could allow the attacker to execute arbitrary code with root -level privileges on the underlying operating system. Cisco has released software updates
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-11-26
Published