Description
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
CVSS breakdown
CVSS 3.0
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Cisco / Cisco Prime Infrastructure3.4 – 3.4
Exploits & proofs of concept
- exploit-dbCisco Prime Infrastructure Health Monitor - TarArchive Directory Traversal (Metasploit)by Metasploit
- exploit-dbCisco Prime Infrastructure Health Monitor HA TarArchive - Directory Traversal / Remote Code Executionby mr_me
- nucleiCisco Prime Infrastructure and Cisco Evolved Programmable Network Manager - Remote Code Executionby _0xf4n9x_
Updated 44m ago · 8 sources