cbcvebase.

Cisco Prime Infrastructure vulnerabilities

50 known vulnerabilities affecting cisco/cisco_prime_infrastructure.

Total CVEs
50
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH7MEDIUM40

Vulnerabilities

Page 3 of 3
CVE-2023-20130P4MEDIUMCVSS 6.5vn/a2023-04-05
CVE-2023-20130 [MEDIUM] CWE-27 CVE-2023-20130: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2021-34784P4MEDIUMCVSS 5.4vn/a2021-11-04
CVE-2021-34784 [MEDIUM] CWE-79 CVE-2021-34784: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability exists because
nvd
CVE-2023-20131P4MEDIUMCVSS 5.4vn/a2023-04-05
CVE-2023-20131 [MEDIUM] CWE-27 CVE-2023-20131: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2026-20075P4MEDIUMCVSS 4.8v3.0.0v3.1.0+150 more2026-01-15
CVE-2026-20075 [MEDIUM] CWE-79 CVE-2026-20075: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the web-based management i
nvd
CVE-2026-20111P4MEDIUMCVSS 4.8v3.0.0v3.1.0+148 more2026-02-04
CVE-2026-20111 [MEDIUM] CWE-798 CVE-2026-20111: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an a A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the web-based management interface does not properly validate user-supplied in
nvd
CVE-2025-20203P4MEDIUMCVSS 4.8v2.0.0v2.0.10+145 more2025-04-02
CVE-2025-20203 [MEDIUM] CWE-79 CVE-2025-20203: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. The vulnerability exists because the web-based management int
nvd
CVE-2025-20280P4MEDIUMCVSS 4.8v3.0.0v3.1.0+72 more2025-09-03
CVE-2025-20280 [MEDIUM] CWE-79 CVE-2025-20280: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the web-based management i
nvd
CVE-2023-20257P4MEDIUMCVSS 4.8v2.0.0v2.0.10+141 more2024-01-17
CVE-2023-20257 [MEDIUM] CWE-80 CVE-2023-20257: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an a A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by submitting malicious i
nvd
CVE-2018-15432P4MEDIUMCVSS 4.3vn/a2018-10-05
CVE-2018-15432 [MEDIUM] CWE-200 CVE-2018-15432: A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authentic A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. A succes
nvd
CVE-2018-15433P4MEDIUMCVSS 4.3vn/a2018-10-05
CVE-2018-15433 [MEDIUM] CWE-200 CVE-2018-15433: A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authentic A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. A succes
nvd