Cisco Evolved Programmable Network Manager vulnerabilities

50 known vulnerabilities affecting cisco/evolved_programmable_network_manager.

Total CVEs
50
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH12MEDIUM32LOW1

Vulnerabilities

Page 2 of 3
CVE-2023-20129MEDIUMCVSS 6.5fixed in 5.0.2.5≥ 5.1, < 5.1.4.2+2 more2023-04-05
CVE-2023-20129 [MEDIUM] CWE-27 CVE-2023-20129: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2023-20130MEDIUMCVSS 6.5fixed in 5.0.2.5≥ 5.1, < 5.1.4.2+2 more2023-04-05
CVE-2023-20130 [MEDIUM] CWE-27 CVE-2023-20130: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2023-20121MEDIUMCVSS 6.7fixed in 7.0.12023-04-05
CVE-2023-20121 [MEDIUM] CWE-77 CVE-2023-20121: Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more information about these vulnerabil
nvd
CVE-2023-20131MEDIUMCVSS 5.4fixed in 5.0.2.5≥ 5.1, < 5.1.4.2+2 more2023-04-05
CVE-2023-20131 [MEDIUM] CWE-27 CVE-2023-20131: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2023-20069MEDIUMCVSS 5.4fixed in 7.02023-03-03
CVE-2023-20069 [MEDIUM] CWE-79 CVE-2023-20069: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user
nvd
CVE-2022-20659MEDIUMCVSS 6.1fixed in 6.02022-02-17
CVE-2022-20659 [MEDIUM] CWE-79 CVE-2022-20659: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interf
nvd
CVE-2021-44228CRITICALCVSS 10.0KEVPoC≤ 4.1.1v3.0+5 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2021-34784MEDIUMCVSS 5.4fixed in 5.1.22021-11-04
CVE-2021-34784 [MEDIUM] CWE-79 CVE-2021-34784: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability exists because
nvd
CVE-2021-34733MEDIUMCVSS 5.5fixed in 5.02021-09-02
CVE-2021-34733 [MEDIUM] CWE-522 CVE-2021-34733: A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists because sensitive information is not sufficiently secured when it is stored. A
nvd
CVE-2021-34707MEDIUMCVSS 6.5≤ 5.02021-08-04
CVE-2021-34707 [MEDIUM] CWE-200 CVE-2021-34707: A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when responding to an API request. An attacker could exploit the vulnerability
nvd
CVE-2021-1487HIGHCVSS 8.8fixed in 5.12021-05-22
CVE-2021-1487 [HIGH] CWE-78 CVE-2021-1487: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Prog A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to insufficient validation of user-supplied input to the web-based management interface. An attacker
nvd
CVE-2021-1306LOWCVSS 3.4fixed in 5.0.12021-05-22
CVE-2021-1306 [MEDIUM] CWE-73 CVE-2021-1306: A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco I A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and write arbitrary files to the file system. This vulnerability is due to improper validation of parameters that are sent
nvd
CVE-2019-15958CRITICALCVSS 9.8fixed in 3.0.22019-11-26
CVE-2019-15958 [CRITICAL] CWE-20 CVE-2019-15958: A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Ne A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA)
nvd
CVE-2019-1821CRITICALCVSS 9.8PoCfixed in 3.0.12019-05-16
CVE-2019-1821 [HIGH] CWE-20 CVE-2019-1821: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
nvd
CVE-2019-1824HIGHCVSS 8.1fixed in 3.0.12019-05-16
CVE-2019-1824 [HIGH] CWE-89 CVE-2019-1824: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this
nvd
CVE-2019-1823HIGHCVSS 7.2fixed in 3.0.12019-05-16
CVE-2019-1823 [HIGH] CWE-20 CVE-2019-1823: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
nvd
CVE-2019-1822HIGHCVSS 7.2fixed in 3.0.12019-05-16
CVE-2019-1822 [HIGH] CWE-20 CVE-2019-1822: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
nvd
CVE-2019-1825HIGHCVSS 8.1fixed in 3.0.12019-05-16
CVE-2019-1825 [HIGH] CWE-89 CVE-2019-1825: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this
nvd
CVE-2019-1819MEDIUMCVSS 6.5fixed in 3.0.12019-05-16
CVE-2019-1819 [MEDIUM] CWE-22 CVE-2019-1819: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in HTTP req
nvd
CVE-2019-1820MEDIUMCVSS 6.5fixed in 3.0.12019-05-16
CVE-2019-1820 [MEDIUM] CWE-22 CVE-2019-1820: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in HTTP req
nvd