← Vulnerability feed

Vulnerability record · CVE-2018-15379 · published 5 October 2018

CVE-2018-15379: Cisco Prime Infrastructure web server directory permission flaw allows file upload

Cisco · Prime Infrastructure

Cisco Prime Infrastructure's HTTP web server has incorrect permission settings on important system directories, letting an unauthenticated remote attacker upload arbitrary files via TFTP reachable through the web GUI. Uploaded files can then be executed as the prime user, giving command execution on the application. The flaw matters because it needs no credentials and no user interaction, and the affected product is a central management platform.

9.8 CVSS 3.0 Critical EPSS 86% · top 0.3% CWE-275 · CWE-275CWE-732 · Incorrect permission assignment
9.8CVSS 3.0 base score, v2 7.5
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This user does not have administrative or root privileges. The vulnerability is due to an incorrect permission setting for important system directories. An attacker could exploit this vulnerability by uploading a malicious file by using TFTP, which can be accessed via the web-interface GUI. A successful exploit could allow the attacker to run commands on the targeted application without authentication.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, very high EPSS, and public exploit code make this a high-urgency issue for exposed Prime Infrastructure instances.

What it is

Cisco Prime Infrastructure's HTTP web server has incorrect permission settings on important system directories, letting an unauthenticated remote attacker upload arbitrary files via TFTP reachable through the web GUI. Uploaded files can then be executed as the prime user, giving command execution on the application. The flaw matters because it needs no credentials and no user interaction, and the affected product is a central management platform.

Impact

An attacker gains remote command execution at the privilege level of the prime user, which is not administrative or root. That access can be used to run commands on the targeted application and potentially pivot within the managed environment.

Attack surface

Reachable over the network through the Prime Infrastructure web interface, specifically the TFTP function exposed via the GUI. No authentication and no user interaction are required per the CVSS vector and description.

Exploitation

Not listed in CISA KEV, but EPSS is very high at 0.862 (99.7th percentile) and a public Exploit-DB entry (45555) exists, indicating mature public exploit code. No ransomware group usage is documented in the record.

What to do

  • Apply the Cisco vendor advisory fix for cisco-sa-20181003-pi-tftp as the first action.
  • Restrict network access to the Prime Infrastructure web interface and TFTP service to trusted management networks only.
  • Disable or block TFTP through the web GUI if it is not operationally required.
  • Audit and correct directory permission settings on Prime Infrastructure system directories.
  • Monitor the prime user account for unexpected command execution or file changes.

Detection

  • Alert on file uploads or TFTP transfers to Prime Infrastructure system directories outside normal change windows.
  • Monitor for processes or commands spawned by the prime user that are not part of expected application behavior.
  • Review web server and TFTP logs for unauthenticated upload requests to the Prime Infrastructure GUI.
  • Watch for new or modified files in directories writable by the web server that could be executed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15379 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2019-15958Cisco prime infrastructure improper input validation vulnerabilityA vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticat…EPSS 3.3%9.8CVE-2019-1821Cisco Prime Infrastructure and EPN Manager input validation RCECisco Prime Infrastructure and Evolved Programmable Network Manager fail to properly validate user-supplied input in the web-based management interfa…EPSS 98%analysed9.8CVE-2018-0258Cisco Prime file upload servlet path traversal and arbitrary file executionThe Cisco Prime File Upload servlet in Cisco Prime Data Center Network Manager (10.0 and later) and Cisco Prime Infrastructure (all versions) allows …EPSS 48%analysed9.8CVE-2016-1289Cisco prime infrastructure memory buffer overflow vulnerabilityThe API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrar…EPSS 6.2%9.8CVE-2016-1291Cisco evolved programmable network manager improper input validation vulnerabilityCisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary…EPSS 6.8%9.0CVE-2014-0679Cisco prime infrastructure improper input validation vulnerabilityCisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to ex…EPSS 2.1%8.8CVE-2021-1487Cisco evolved programmable network manager os command injection vulnerabilityA vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an aut…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2018-15379), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.