CVE-2019-1821

High PUBLISHED

Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities

Vendor: Cisco Product: Cisco Prime Infrastructure

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.8 High EPSS 98.1%

At a Glance

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.

nuclei_scanner
CVE Published
May 16, 2019
Exploitation Reported
Jun 08, 2025
CVSS
8.8 High
EPSS
98.1%
Remote Low complexity No user interaction

Affected Versions

Vendor Product Version Status
Cisco
Cisco Prime Infrastructure

3.4

Affected

CVE References