Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1821

Опубликовано: 16 мая 2019
Источник: nvd
CVSS3: 8.8
CVSS3: 9.8
CVSS2: 10
EPSS Критический

Описание

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*
Версия до 3.0.1 (исключая)
cpe:2.3:a:cisco:network_level_service:3.0\(0.0.83b\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:*:*:*:*:*:*:*:*
Версия до 3.4.1 (исключая)

EPSS

Процентиль: 100%
0.94044
Критический

8.8 High

CVSS3

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.

CVSS3: 9.8
fstec
больше 6 лет назад

Уязвимость веб-интерфейса администрирования системы мониторинга и управления сетевым оборудованием Cisco Prime Infrastructure и программного средства управления сетевыми сервисами Cisco Evolved Programmable Network Manager, позволяющая нарушителю выполнить произвольный код с привилегиями root

EPSS

Процентиль: 100%
0.94044
Критический

8.8 High

CVSS3

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-20
CWE-20