Cisco Prime Infrastructure vulnerabilities
50 known vulnerabilities affecting cisco/cisco_prime_infrastructure.
Total CVEs
50
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH7MEDIUM40
Vulnerabilities
Page 2 of 3
CVE-2023-20129P4MEDIUMCVSS 6.5vn/a2023-04-05
CVE-2023-20129 [MEDIUM] CWE-27 CVE-2023-20129: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2023-20127P4MEDIUMCVSS 6.5vn/a2023-04-05
CVE-2023-20127 [MEDIUM] CWE-27 CVE-2023-20127: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2023-20260P4MEDIUMCVSS 6.7v2.0.0v2.0.10+141 more2024-01-17
CVE-2023-20260 [MEDIUM] CWE-284 CVE-2023-20260: A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing of command line arguments to application scripts. An attacker could exploit this vulnerability by issuing a comm
nvd
CVE-2022-20657P4MEDIUMCVSS 6.1v3.0.0v3.1.0+14 more2024-11-15
CVE-2022-20657 [MEDIUM] CWE-79 CVE-2022-20657: A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could all
A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device.
This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit
nvd
CVE-2022-20659P4MEDIUMCVSS 6.1vn/a2022-02-17
CVE-2022-20659 [MEDIUM] CWE-79 CVE-2022-20659: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interf
nvd
CVE-2025-20120P4MEDIUMCVSS 6.1v2.0.0v2.0.10+145 more2025-04-02
CVE-2025-20120 [MEDIUM] CWE-79 CVE-2025-20120: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.
This vulnerability is due to insufficient validation of us
nvd
CVE-2023-20068P4MEDIUMCVSS 6.1vn/a2023-04-05
CVE-2023-20068 [MEDIUM] CWE-79 CVE-2023-20068: A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could a
A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could expl
nvd
CVE-2023-20222P4MEDIUMCVSS 6.1v2.0.0v2.0.10+139 more2023-08-16
CVE-2023-20222 [MEDIUM] CWE-80 CVE-2023-20222: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device.
The vulnerability is due to insufficient validation of user-supp
nvd
CVE-2023-20203P4MEDIUMCVSS 5.4v2.0.0v2.0.10+139 more2023-08-16
CVE-2023-20203 [MEDIUM] CWE-79 CVE-2023-20203: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.
These vulnerabilities are due to insufficient vali
nvd
CVE-2023-20205P4MEDIUMCVSS 5.4v2.0.0v2.0.10+139 more2023-08-16
CVE-2023-20205 [MEDIUM] CWE-79 CVE-2023-20205: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.
These vulnerabilities are due to insufficient vali
nvd
CVE-2023-20201P4MEDIUMCVSS 5.4v2.0.0v2.0.10+139 more2023-08-16
CVE-2023-20201 [MEDIUM] CWE-79 CVE-2023-20201: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.
These vulnerabilities are due to insufficient vali
nvd
CVE-2026-20189P4MEDIUMCVSS 4.3v3.6.0v3.7.0+63 more2026-05-06
CVE-2026-20189 [MEDIUM] CWE-862 CVE-2026-20189: A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an&
A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server.
This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this vulnerability by submitting a crafted URL reque
nvd
CVE-2019-1643P4MEDIUMCVSS 6.1vn/a2019-01-23
CVE-2019-1643 [MEDIUM] CWE-79 CVE-2019-1643: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an u
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based mana
nvd
CVE-2018-15457P4MEDIUMCVSS 6.1vn/a2019-01-10
CVE-2018-15457 [MEDIUM] CWE-79 CVE-2018-15457: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an u
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based manag
nvd
CVE-2019-12713P4MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-02
CVE-2019-12713 [MEDIUM] CWE-79 CVE-2019-12713: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an u
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based ma
nvd
CVE-2019-12712P4MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-02
CVE-2019-12712 [MEDIUM] CWE-79 CVE-2019-12712: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an u
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input in multiple section
nvd
CVE-2021-34733P4MEDIUMCVSS 5.5vn/a2021-09-02
CVE-2021-34733 [MEDIUM] CWE-522 CVE-2021-34733: A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN
A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists because sensitive information is not sufficiently secured when it is stored. A
nvd
CVE-2023-20069P4MEDIUMCVSS 5.4vn/a2023-03-03
CVE-2023-20069 [MEDIUM] CWE-79 CVE-2023-20069: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user
nvd
CVE-2024-20514P4MEDIUMCVSS 5.4v3.0.0v3.1.0+146 more2024-11-06
CVE-2024-20514 [MEDIUM] CWE-79 CVE-2024-20514: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability exists because the web-based management interf
nvd
CVE-2025-20272P4MEDIUMCVSS 4.3v3.0.0v3.1.0+148 more2025-07-16
CVE-2025-20272 [MEDIUM] CWE-89 CVE-2025-20272: A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmabl
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability b
nvd