{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:40:39Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"cisco-sa-20190619-prime-privescal","slug":"cisco-sa-20190619-prime-privescal","vendor":"Cisco","title":"Cisco Prime Infrastructure and Evolved Programmable Network Manager Virtual Domain Privilege Escalation Vulnerability","summary":"A vulnerability in the Virtual Domain system of Cisco&nbsp;Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPN Manager) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by manipulating requests sent to an affected PI server. A successful exploit could allow the attacker to change the virtual domain configuration and possibly elevate privileges. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190619-prime-privescal","severity":"Medium","published_at":"2019-06-19T16:00:00Z","updated_at":"2019-07-03T15:48:44Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190619-prime-privescal","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/cisco-sa-20190619-prime-privescal/csaf/cisco-sa-20190619-prime-privescal.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":2,"public_evidence_count":2,"kev_count":0,"highest_epss":0.01274},"cves":[{"id":"CVE-2019-1906","kev":false,"epss":{"score":0.01274,"percentile":0.66655,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:48Z"}}],"public_evidence":[{"product":{"name":"Cisco Prime Infrastructure","slug":"cisco-prime-infrastructure","vendor":"Cisco"},"cve":{"id":"CVE-2019-1906"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T00:00:28Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Prime Infrastructure","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.01274,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:48Z"},"published_at":"2019-06-19T16:00:00Z","updated_at":"2019-07-03T15:48:44Z","advisory_updated_at":"2019-07-03T15:48:44Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190619-prime-privescal","remediation":{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190619-prime-privescal"},"row_display_order":1},{"product":{"name":"Cisco Evolved Programmable Network Manager (EPNM)","slug":"cisco-evolved-programmable-network-manager-epnm","vendor":"Cisco"},"cve":{"id":"CVE-2019-1906"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T00:00:28Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Evolved Programmable Network Manager (EPNM)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.01274,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:48Z"},"published_at":"2019-06-19T16:00:00Z","updated_at":"2019-07-03T15:48:44Z","advisory_updated_at":"2019-07-03T15:48:44Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190619-prime-privescal","remediation":{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190619-prime-privescal"},"row_display_order":2}]}