CVE Database
/

CVE-2018-15379

Back to search

CVE-2018-15379

Published: Oct 5, 2018

Modified: Nov 26, 2024

PUBLISHED

Description

A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This user does not have administrative or root privileges. The vulnerability is due to an incorrect permission setting for important system directories. An attacker could exploit this vulnerability by uploading a malicious file by using TFTP, which can be accessed via the web-interface GUI. A successful exploit could allow the attacker to run commands on the targeted application without authentication.

VendorProductVersions

Cisco

Cisco Prime Infrastructure

affected
n/a

Weaknesses (CWE)

References

45555
exploit
x_refsource_EXPLOIT-DB
105506
vdb-entry
x_refsource_BID
1041816
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now