CVE-2019-1819 (CNNVD-201905-696)
中文标题:
Cisco Prime Infrastructure Software和Cisco Evolved Programmable Network Manager 路径遍历漏洞
英文标题:
Cisco Prime Infrastructure and Evolved Programmable Network Manager Path Traversal Vulnerability
漏洞描述
中文描述:
Cisco Prime Infrastructure Software和Cisco Evolved Programmable Network Manager都是美国思科(Cisco)公司的产品。Cisco Prime Infrastructure Software是一套通过Cisco Prime LAN Management Solution(LMS)和Cisco Prime Network Control System(NCS)技术进行无线管理的软件。Cisco Evolved Programmable Network Manager是一套网络管理解决方案。 Cisco Evolved Programmable Network Manager和Cisco Prime Infrastructure Software中存在路径遍历漏洞。该漏洞源于网络系统或产品未能正确地过滤资源或文件路径中的特殊元素。攻击者可利用该漏洞访问受限目录之外的位置。
英文描述:
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view application files that may contain sensitive information.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Prime Infrastructure | 3.4 | - | - |
cpe:2.3:a:cisco:cisco_prime_infrastructure:3.4:*:*:*:*:*:*:*
|
| cisco | evolved_programmable_network_manager | * | - | - |
cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*
|
| cisco | prime_infrastructure | * | - | - |
cpe:2.3:a:cisco:prime_infrastructure:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-1819 |
2025-11-11 15:20:08 | 2025-11-11 07:35:39 |
| NVD | nvd_CVE-2019-1819 |
2025-11-11 14:56:22 | 2025-11-11 07:44:10 |
| CNNVD | cnnvd_CNNVD-201905-696 |
2025-11-11 15:10:12 | 2025-11-11 07:54:33 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 路径遍历
- cnnvd_id: 未提取 -> CNNVD-201905-696
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']