CVE-2019-1825 is a high-severity SQL injection vulnerability affecting the web-based management interfaces of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager. An authenticated, remote attacker can exploit improper input validation to execute arbitrary SQL queries. This allows for viewing or modifying database entries, impacting data integrity. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available, the vulnerability has garnered some community discussion and media coverage, though it is not listed on the KEV catalog as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:* | ||
3.0\(0.0.83b\)CPE matchmatch criteria | cpe:2.3:a:cisco:network_level_service:3.0\(0.0.83b\):*:*:*:*:*:*:* | ||
< 3.4.1CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.