CVE-2019-1906
published 2019-06-20CVE-2019-1906: A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual domain…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.27%
66.6th percentile
A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by manipulating requests sent to an affected PI server. A successful exploit could allow the attacker to change the virtual domain configuration and possibly elevate privileges.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure_and_evolved_programmable_network_manager_virtual_domain | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hm4-qrp4-v66v: A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual do
ghsa_unreviewed·2022-05-24
CVE-2019-1906 [MEDIUM] GHSA-2hm4-qrp4-v66v: A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual do
A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by manipulating requests sent to an affected PI server. A successful exploit could allow the attacker to change the virtual domain configuration and possibly elevate privileges.
Citrix
CVE-2019-12292: Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
vendor_citrix·2019-06-24·CVSS 9.8
CVE-2019-12292 [CRITICAL] CVE-2019-12292: Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
CVE-2019-12292: Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Virtual Domain Privilege Escalation Vulnerability
vendor_cisco·2019-06-19·CVSS 4.3
CVE-2019-1906 [MEDIUM] CWE-20 Cisco Prime Infrastructure and Evolved Programmable Network Manager Virtual Domain Privilege Escalation Vulnerability
Cisco Prime Infrastructure and Evolved Programmable Network Manager Virtual Domain Privilege Escalation Vulnerability
A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPN Manager) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation.
The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by manipulating requests sent to an affected PI server. A successful exploit could allow the attacker to change the virtual domain configuration and possibly elevate privileges.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.clouda
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Virtual Domain Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1906 Cisco Prime Infrastructure and Evolved Programmable Network Manager Virtual Domain Privilege Escalation Vulnerability
CVE-2019-1906: Cisco Prime Infrastructure and Evolved Programmable Network Manager Virtual Domain Privilege Escalation Vulnerability
A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPN Manager) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by manipulating requests sent to an affected PI server. A successful exploit could allow the attacker to change the virtual domain configuration and possibly elevate privileges. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvo46881, CSCvq37787
Citrix
CVE-2019-11634 - Improper Access Control Vulnerability in AppDNA
vendor_citrix·CVSS 9.8
CVE-2019-11634 [CRITICAL] CVE-2019-11634 - Improper Access Control Vulnerability in AppDNA
CVE-2019-11634 - Improper Access Control Vulnerability in AppDNA
of Problem A vulnerability has been identified in AppDNA that could result in access controls not being enforced when accessing the web console potentially allowing privilege escalation and remote code execution. This vulnerability has been assigned the following CVE number: • CVE-2019-12292: Improper Access Control in AppDNA prior to version 7 1906.1.0.472. This vulnerability is present in all versions of AppDNA up to and including 7.18
CVE References: CVE-2019-11634, CVE-2019-12292
Affected Products: XenServer
Severity: High
Remediation:
This vulnerability has been addressed in AppDNA version 7 1906.1.0.472 and above. Citrix recommends that customers upgrade AppDNA to version 7 1906.1.0.472 and above, and configure IIS a
No detection rules found.
No public exploits indexed.
2019-06-20
Published