CVE-2019-1659 describes a vulnerability in Cisco Prime Infrastructure (PI) versions 2.2 through 3.4.0 when integrated with Cisco Identity Services Engine (ISE). This flaw, due to improper SSL certificate validation, allows an unauthenticated, remote attacker to perform a man-in-the-middle attack on the SSL tunnel between PI and ISE. The vulnerability has a CVSS score of 7.4 (High), indicating high confidentiality and integrity impact, as an attacker could intercept and alter sensitive network client information. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in CISA's KEV catalog, there has been limited community discussion and media coverage, suggesting it is not actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2, <= 3.4.0CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.