PT-2018-2097 · Cisco · Cisco Prime Infrastructure

Pedro Ribeiro

·

Published

2018-10-03

·

Updated

2019-10-09

·

CVE-2018-15379

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Prime Infrastructure (affected versions not specified)
Description A vulnerability exists due to incorrect permission settings for important system directories in the HTTP web server for Cisco Prime Infrastructure. This could allow an unauthenticated, remote attacker to upload an arbitrary file, potentially enabling the execution of commands at the privilege level of the user 'prime', which does not have administrative or root privileges. The vulnerability can be exploited by uploading a malicious file using TFTP, accessible via the web-interface GUI. A successful exploit could allow the attacker to run commands on the targeted application without authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00048
CVE-2018-15379

Affected Products

Cisco Prime Infrastructure