Back

CVE-2019-15958

CRITICAL

A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA) configuration and registration process of an affected device. An attacker could exploit this vulnerability by uploading a malicious file during the HA registration period. A successful exploit could allow the attacker to execute arbitrary code with root-level privileges on the underlying operating system. Note: This vulnerability can only be exploited during the HA registration period. See the Details section for more information.

Published: Nov 26, 2019 Modified: Jun 17, 2026
CWE-20 CWE-20

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
cisco prime_infrastructure * < 3.4.2
cisco prime_infrastructure * ≥ 3.5 < 3.5.1
cisco prime_infrastructure 3.6
cisco evolved_programmable_network_manager * < 3.0.2

GitHub Security Advisory GHSA-4gj6-pp76-wxr5

A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.29%

Top 12% most likely to be exploited

Threat Score 40.2 / 100

Data Sources

NVD EPSS GitHub