CVE-2019-1821: Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-1821.
What is the severity of CVE-2019-1821?
The severity of CVE-2019-1821 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2019-1821?
The affected software for CVE-2019-1821 includes Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager.
How does this vulnerability allow an attacker to execute code with root-level privileges?
This vulnerability allows an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system.
How can I fix CVE-2019-1821?
To fix CVE-2019-1821, it is recommended to apply the necessary patches or updates provided by Cisco.