Cisco Prime Infrastructure vulnerabilities
49 known vulnerabilities affecting cisco/cisco_prime_infrastructure.
Total CVEs
49
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH7MEDIUM39
Vulnerabilities
Page 2 of 3
CVE-2023-20068MEDIUMCVSS 6.1vn/a2023-04-05
CVE-2023-20068 [MEDIUM] CWE-79 CVE-2023-20068: A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could a
A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could expl
cvelistv5nvd
CVE-2023-20131MEDIUMCVSS 5.4vn/a2023-04-05
CVE-2023-20131 [MEDIUM] CWE-27 CVE-2023-20131: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
cvelistv5nvd
CVE-2023-20130MEDIUMCVSS 6.5vn/a2023-04-05
CVE-2023-20130 [MEDIUM] CWE-27 CVE-2023-20130: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
cvelistv5nvd
CVE-2023-20129MEDIUMCVSS 6.5vn/a2023-04-05
CVE-2023-20129 [MEDIUM] CWE-27 CVE-2023-20129: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
cvelistv5nvd
CVE-2023-20127MEDIUMCVSS 6.5vn/a2023-04-05
CVE-2023-20127 [MEDIUM] CWE-27 CVE-2023-20127: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
cvelistv5nvd
CVE-2023-20069MEDIUMCVSS 5.4vn/a2023-03-03
CVE-2023-20069 [MEDIUM] CWE-79 CVE-2023-20069: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user
cvelistv5nvd
CVE-2022-20659MEDIUMCVSS 6.1vn/a2022-02-17
CVE-2022-20659 [MEDIUM] CWE-79 CVE-2022-20659: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interf
cvelistv5nvd
CVE-2021-34784MEDIUMCVSS 5.4vn/a2021-11-04
CVE-2021-34784 [MEDIUM] CWE-79 CVE-2021-34784: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability exists because
cvelistv5nvd
CVE-2021-34733MEDIUMCVSS 5.5vn/a2021-09-02
CVE-2021-34733 [MEDIUM] CWE-522 CVE-2021-34733: A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN
A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists because sensitive information is not sufficiently secured when it is stored. A
cvelistv5nvd
CVE-2021-1487HIGHCVSS 8.8vn/a2021-05-22
CVE-2021-1487 [HIGH] CWE-78 CVE-2021-1487: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Prog
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to insufficient validation of user-supplied input to the web-based management interface. An attacker
cvelistv5nvd
CVE-2020-3339MEDIUMCVSS 5.4vn/a2020-06-03
CVE-2020-3339 [MEDIUM] CWE-89 CVE-2020-3339: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an a
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and send
cvelistv5nvd
CVE-2019-15958CRITICALCVSS 9.8≥ unspecified, < n/a2019-11-26
CVE-2019-15958 [CRITICAL] CWE-20 CVE-2019-15958: A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Ne
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA)
cvelistv5nvd
CVE-2019-12713MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-02
CVE-2019-12713 [MEDIUM] CWE-79 CVE-2019-12713: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an u
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based ma
cvelistv5nvd
CVE-2019-12712MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-02
CVE-2019-12712 [MEDIUM] CWE-79 CVE-2019-12712: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an u
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input in multiple section
cvelistv5nvd
CVE-2019-1906MEDIUMCVSS 6.5v3.6(0.0)2019-06-20
CVE-2019-1906 [MEDIUM] CWE-264 CVE-2019-1906: A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authe
A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by manipulating requests sent t
cvelistv5nvd
CVE-2019-1821CRITICALCVSS 9.8PoCv3.42019-05-16
CVE-2019-1821 [HIGH] CWE-20 CVE-2019-1821: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
cvelistv5nvd
CVE-2019-1823HIGHCVSS 7.2v3.42019-05-16
CVE-2019-1823 [HIGH] CWE-20 CVE-2019-1823: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
cvelistv5nvd
CVE-2019-1824HIGHCVSS 8.1v3.42019-05-16
CVE-2019-1824 [HIGH] CWE-89 CVE-2019-1824: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this
cvelistv5nvd
CVE-2019-1822HIGHCVSS 7.2v3.42019-05-16
CVE-2019-1822 [HIGH] CWE-20 CVE-2019-1822: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
cvelistv5nvd
CVE-2019-1825HIGHCVSS 8.1v3.42019-05-16
CVE-2019-1825 [HIGH] CWE-89 CVE-2019-1825: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this
cvelistv5nvd