CVE-2019-15958
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA) configuration and registration process of an affected device. An attacker could exploit this vulnerability by uploading a malicious file during the HA registration period. A successful exploit could allow the attacker to execute arbitrary code with root-level privileges on the underlying operating system. Note: This vulnerability can only be exploited during the HA registration period. See the Details section for more information.
Una vulnerabilidad en la API REST de Cisco Prime Infrastructure (PI) y Cisco Evolved Programmable Network Manager (EPNM), podría permitir a un atacante remoto no autenticado ejecutar código arbitrario con privilegios root en el sistema operativo subyacente. La vulnerabilidad es debido a una comprobación de entrada insuficiente durante la configuración inicial de alta disponibilidad (HA) y el proceso de registro de un dispositivo afectado. Un atacante podría explotar esta vulnerabilidad al cargar un archivo malicioso durante el período de registro de HA. Una explotación con éxito podría permitir al atacante ejecutar código arbitrario con privilegios de nivel root en el sistema operativo subyacente. Nota: Esta vulnerabilidad solo puede ser explotada durante el período de registro de HA. Vea la sección Detalles para más información.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2019-09-06 CVE Reserved
- 2019-11-26 CVE Published
- 2024-01-04 EPSS Updated
- 2024-11-20 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Prime Infrastructure Search vendor "Cisco" for product "Prime Infrastructure" | < 3.4.2 Search vendor "Cisco" for product "Prime Infrastructure" and version " < 3.4.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Infrastructure Search vendor "Cisco" for product "Prime Infrastructure" | >= 3.5 < 3.5.1 Search vendor "Cisco" for product "Prime Infrastructure" and version " >= 3.5 < 3.5.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Prime Infrastructure Search vendor "Cisco" for product "Prime Infrastructure" | 3.6 Search vendor "Cisco" for product "Prime Infrastructure" and version "3.6" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Evolved Programmable Network Manager Search vendor "Cisco" for product "Evolved Programmable Network Manager" | < 3.0.2 Search vendor "Cisco" for product "Evolved Programmable Network Manager" and version " < 3.0.2" | - |
Affected
|