CVE-2019-1819

Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 16 May 2019, 01:10
Last modified:21 Nov 2024, 19:24

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
6.5 MEDIUM
v3.0 (cve.org)
EPSS Score
10.72% MEDIUM
11% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 May 2019, 01:10
Published
Vulnerability first disclosed
21 Nov 2024, 19:24
Last Modified
Vulnerability information updated

Description

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view application files that may contain sensitive information.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • v3.0MEDIUMScore: 6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 10.72% Percentile: 93%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • ciscocisco prime infrastructure

    3.4

  • ciscoevolved_programmable_network_manager

    < 3.0.1

  • ciscoprime_infrastructure

    < 3.4

References (2)