Lucene search

K
cveCiscoCVE-2019-1819
HistoryMay 16, 2019 - 1:29 a.m.

CVE-2019-1819

2019-05-1601:29:00
CWE-22
cisco
web.nvd.nist.gov
39
cisco
prime infrastructure
epn manager
vulnerability
remote attacker
file viewing
input sanitization
http request
directory traversal
sensitive information
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0.002

Percentile

54.8%

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view application files that may contain sensitive information.

Affected configurations

Nvd
Node
ciscoevolved_programmable_network_managerRange<3.0.1
OR
ciscoprime_infrastructureRange<3.4
VendorProductVersionCPE
ciscoevolved_programmable_network_manager*cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*
ciscoprime_infrastructure*cpe:2.3:a:cisco:prime_infrastructure:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco Prime Infrastructure",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "3.4"
      }
    ]
  }
]

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0.002

Percentile

54.8%