9.8

CVE-2018-15379

Exploit

A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This user does not have administrative or root privileges. The vulnerability is due to an incorrect permission setting for important system directories. An attacker could exploit this vulnerability by uploading a malicious file by using TFTP, which can be accessed via the web-interface GUI. A successful exploit could allow the attacker to run commands on the targeted application without authentication.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoPrime Infrastructure Version3.2
CiscoPrime Infrastructure Version3.2 Updatefips
CiscoPrime Infrastructure Version3.2(0.0)
CiscoPrime Infrastructure Version3.2(1.0)
CiscoPrime Infrastructure Version3.2(2.0)
CiscoPrime Infrastructure Version3.3
CiscoPrime Infrastructure Version3.3(0.0)
CiscoPrime Infrastructure Version3.4
CiscoPrime Infrastructure Version3.4(0.0)
CiscoPrime Infrastructure Version3.5(0.0)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 89.68% 0.995
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.