Vulnerability record · CVE-2018-15379 · published 5 October 2018
CVE-2018-15379: Cisco Prime Infrastructure web server directory permission flaw allows file upload
Cisco · Prime Infrastructure
Cisco Prime Infrastructure's HTTP web server has incorrect permission settings on important system directories, letting an unauthenticated remote attacker upload arbitrary files via TFTP reachable through the web GUI. Uploaded files can then be executed as the prime user, giving command execution on the application. The flaw matters because it needs no credentials and no user interaction, and the affected product is a central management platform.
Description
A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This user does not have administrative or root privileges. The vulnerability is due to an incorrect permission setting for important system directories. An attacker could exploit this vulnerability by uploading a malicious file by using TFTP, which can be accessed via the web-interface GUI. A successful exploit could allow the attacker to run commands on the targeted application without authentication.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, very high EPSS, and public exploit code make this a high-urgency issue for exposed Prime Infrastructure instances.
What it is
Cisco Prime Infrastructure's HTTP web server has incorrect permission settings on important system directories, letting an unauthenticated remote attacker upload arbitrary files via TFTP reachable through the web GUI. Uploaded files can then be executed as the prime user, giving command execution on the application. The flaw matters because it needs no credentials and no user interaction, and the affected product is a central management platform.
Impact
An attacker gains remote command execution at the privilege level of the prime user, which is not administrative or root. That access can be used to run commands on the targeted application and potentially pivot within the managed environment.
Attack surface
Reachable over the network through the Prime Infrastructure web interface, specifically the TFTP function exposed via the GUI. No authentication and no user interaction are required per the CVSS vector and description.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.862 (99.7th percentile) and a public Exploit-DB entry (45555) exists, indicating mature public exploit code. No ransomware group usage is documented in the record.
What to do
- Apply the Cisco vendor advisory fix for cisco-sa-20181003-pi-tftp as the first action.
- Restrict network access to the Prime Infrastructure web interface and TFTP service to trusted management networks only.
- Disable or block TFTP through the web GUI if it is not operationally required.
- Audit and correct directory permission settings on Prime Infrastructure system directories.
- Monitor the prime user account for unexpected command execution or file changes.
Detection
- Alert on file uploads or TFTP transfers to Prime Infrastructure system directories outside normal change windows.
- Monitor for processes or commands spawned by the prime user that are not part of expected application behavior.
- Review web server and TFTP logs for unauthenticated upload requests to the Prime Infrastructure GUI.
- Watch for new or modified files in directories writable by the web server that could be executed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/105506 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041816 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-pi-tftp | Vendor Advisory |
| https://www.exploit-db.com/exploits/45555/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/105506 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041816 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-pi-tftp | Vendor Advisory |
| https://www.exploit-db.com/exploits/45555/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-15379 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-15379), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.