PT-2019-2661 · Cisco · Cisco Evolved Programmable Network (Epn) Manager+1

Published

2019-06-19

·

Updated

2020-10-16

·

CVE-2019-1906

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Prime Infrastructure versions (affected versions not specified) Cisco Evolved Programmable Network (EPN) Manager versions (affected versions not specified)
Description The issue is related to errors in API request validation in the Virtual Domain component of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager. This could allow a remote attacker to modify the virtual domain configuration and potentially elevate privileges. The vulnerability can be exploited by manipulating API requests sent to an affected server.
Recommendations For Cisco Prime Infrastructure, update to a version that fixes the improper validation of API requests to prevent configuration changes and privilege escalation. For Cisco Evolved Programmable Network (EPN) Manager, update to a version that fixes the improper validation of API requests to prevent configuration changes and privilege escalation. As a temporary workaround, consider restricting access to the Virtual Domain component until a patch is available. Avoid using the vulnerable API endpoints until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02547
CVE-2019-1906

Affected Products

Cisco Evolved Programmable Network (Epn) Manager
Cisco Prime Infrastructure