CVE-2019-15958 is a critical vulnerability affecting the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM). It allows an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system due to insufficient input validation during the High Availability (HA) configuration and registration process. This vulnerability has a CVSS score of 9.8 (Critical), indicating a network-based attack with low complexity, requiring no user interaction, and leading to complete compromise of confidentiality, integrity, and availability. While the vulnerability can only be exploited during the HA registration period, there is no evidence of active exploitation, nor are there publicly available exploit modules like Metasploit or Nuclei. Despite this, there has been some community discussion and media coverage, suggesting awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.2CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:*:*:*:*:*:*:*:* | ||
>= 3.5, < 3.5.1CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:*:*:*:*:*:*:*:* | ||
3.6CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:3.6:*:*:*:*:*:*:* | ||
< 3.0.2CPE matchmatch criteria | cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.