{"id":"CVE-2019-1821","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-1821","summary":"A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker…","details":"A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.","published":"2019-05-16T01:10:39.996Z","modified":"2024-11-20T17:18:12.432Z","cvss":null,"epss":{"score":0.98051,"percentile":0.99907,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":5,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-pi-rce"},{"type":"WEB","url":"http://www.securityfocus.com/bid/108339"},{"type":"WEB","url":"http://packetstormsecurity.com/files/153350/Cisco-Prime-Infrastructure-Health-Monitor-TarArchive-Directory-Traversal.html"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2024-11-20T17:18:12.432Z"}}