Back

CVE-2018-15379

CRITICAL

A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This user does not have administrative or root privileges. The vulnerability is due to an incorrect permission setting for important system directories. An attacker could exploit this vulnerability by uploading a malicious file by using TFTP, which can be accessed via the web-interface GUI. A successful exploit could allow the attacker to run commands on the targeted application without authentication.

Published: Oct 5, 2018 Modified: Jun 17, 2026
CWE-275 CWE-732

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (10)

Vendor Product Version
cisco prime_infrastructure 3.2
cisco prime_infrastructure 3.2
cisco prime_infrastructure 3.2\(0.0\)
cisco prime_infrastructure 3.2\(1.0\)
cisco prime_infrastructure 3.2\(2.0\)
cisco prime_infrastructure 3.3
cisco prime_infrastructure 3.3\(0.0\)
cisco prime_infrastructure 3.4
cisco prime_infrastructure 3.4\(0.0\)
cisco prime_infrastructure 3.5\(0.0\)

GitHub Security Advisory GHSA-h92j-m24w-8xp7

A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 86.22%

Top 0% most likely to be exploited

Threat Score 75.1 / 100

Data Sources

NVD EPSS GitHub