QID 730115
Date Published: 2021-09-08
QID 730115: Cisco Prime Infrastructure Command Injection Vulnerability(cisco-sa-pi-epnm-cmd-inj-YU5e6tB3)
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and
Evolved Programmable Network (EPN) Manager could allow an authenticated,
remote attacker to execute arbitrary commands on an affected system.
Affected Products
Cisco Prime Infrastructure releases earlier than Release 3.9 and Cisco EPN Manager releases earlier than Release 5.1.
Note: No support for Cisco EPN Manager
QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable Cisco Prime Infrastructure version retrieved via a GET request to a "webacs/js/xmp/nls/xmp.js"
A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system (OS)
with the permissions of a special non-root user. In this way, an attacker
could take control of the affected system, which would allow them to obtain and alter sensitive data.
Customers are advised to refer to cisco-sa-pi-epnm-cmd-inj-YU5e6tB3 for more information.
- cisco-sa-pi-epnm-cmd-inj-YU5e6tB3 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-epnm-cmd-inj-YU5e6tB3
CVEs related to QID 730115
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-pi-epnm-cmd-inj-YU5e6tB3 |
|