CVE-2019-1823
published 2019-05-16CVE-2019-1823: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an…
PriorityP350high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
4.42%
90.2th percentile
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_prime_infrastructure | — | — |
| cisco | evolved_programmable_network_manager | < 3.0.1 | 3.0.1 |
| cisco | network_level_service | — | — |
| cisco | prime_infrastructure | < 3.4.1 | 3.4.1 |
| cisco | prime_infrastructure_and_evolved_programmable_network_manager | — | — |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
vendor_cisco·2019-05-15·CVSS 8.8
CVE-2019-1821 [HIGH] CWE-20 Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow a remote attacker to gain the ability to execute arbitrary code with elevated privileges on the underlying operating system.
One of these issues, CVE-2019-1821, can be exploited by an unauthenticated attacker that has network access to the affected administrative interface.
The second and third issues, CVE-2019-1822 and CVE-2019-1823, require that an attacker have valid credentials to authenticate to the impacted administrative interface.
These vulnerabilities exist because the software improperly validates user-supplied
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2019-1822 Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
CVE-2019-1822: Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow a remote attacker to gain the ability to execute arbitrary code with elevated privileges on the underlying operating system. One of these issues, CVE-2019-1821, can be exploited by an unauthenticated attacker that has network access to the affected administrative interface. The second and third issues, CVE-2019-1822 and CVE-2019-1823, require that an attacker have valid credentials to authenticate to the impacted administrative interface. These vulnerabilities exist because the software improperly validates use
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2019-1823 Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
CVE-2019-1823: Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow a remote attacker to gain the ability to execute arbitrary code with elevated privileges on the underlying operating system. One of these issues, CVE-2019-1821, can be exploited by an unauthenticated attacker that has network access to the affected administrative interface. The second and third issues, CVE-2019-1822 and CVE-2019-1823, require that an attacker have valid credentials to authenticate to the impacted administrative interface. These vulnerabilities exist because the software improperly validates use
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2019-1821 Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
CVE-2019-1821: Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow a remote attacker to gain the ability to execute arbitrary code with elevated privileges on the underlying operating system. One of these issues, CVE-2019-1821, can be exploited by an unauthenticated attacker that has network access to the affected administrative interface. The second and third issues, CVE-2019-1822 and CVE-2019-1823, require that an attacker have valid credentials to authenticate to the impacted administrative interface. These vulnerabilities exist because the software improperly validates use
GHSA
GHSA-wv6g-qwmr-mc4x: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could al
ghsa_unreviewed·2022-05-24
CVE-2019-1823 [HIGH] CWE-20 GHSA-wv6g-qwmr-mc4x: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could al
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
No detection rules found.
No public exploits indexed.
2019-05-16
Published