← Back to browse · API

CVE-2019-1821

Severity
HIGH
CVSS
8.8
EPSS
0.98092
Risk score
69.53
CISA KEV
No
PoC
No
Published
2019-05-16
Modified
2024-11-20
First seen
2026-08-07
Aliases
EUVD-2019-10378, GHSA-4MX6-FJQC-4RHR
Products
Cisco:Cisco Prime Infrastructure 3.4
Sources
euvd EUVD-2019-10378

Description

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.

References