A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
2019-05-16T01:29:00.483
2024-11-21T04:37:28.080
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | cisco | evolved_programmable_network_manager | < 3.0.1 | Yes |
| Application | cisco | network_level_service | 3.0\(0.0.83b\) | Yes |
| Application | cisco | prime_infrastructure | < 3.4.1 | Yes |