CVE-2019-1822: Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1822?
CVE-2019-1822 is a vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager.
What is the severity of CVE-2019-1822?
CVE-2019-1822 has a severity rating of 7.2 (Critical).
How does CVE-2019-1822 impact Cisco Prime Infrastructure?
CVE-2019-1822 allows an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system of Cisco Prime Infrastructure.
How does CVE-2019-1822 impact Cisco Evolved Programmable Network Manager?
CVE-2019-1822 allows an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system of Cisco Evolved Programmable Network Manager.
How can I fix CVE-2019-1822?
Apply the necessary patches and updates provided by Cisco to fix CVE-2019-1822.