cbcvebase.

Cisco Prime Infrastructure vulnerabilities

83 known vulnerabilities affecting cisco/prime_infrastructure.

Total CVEs
83
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH15MEDIUM59LOW2

Vulnerabilities

Page 1 of 5
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in 3.10.42023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2019-1821P1CRITICALCVSS 9.8ExploitedPoCfixed in 3.4.12019-05-16
CVE-2019-1821 [CRITICAL] CWE-20 CVE-2019-1821: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied inpu
nvd
CVE-2018-15379P1CRITICALCVSS 9.8PoCv3.2v3.2\(0.0\)+7 more2018-10-05
CVE-2018-15379 [CRITICAL] CWE-275 CVE-2018-15379: A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted di A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This user does not have administrative or root privileg
nvd
CVE-2018-0258P2CRITICALCVSS 9.8v3.3\(0.0\)2018-05-02
CVE-2018-0258 [CRITICAL] CWE-22 CVE-2018-0258: A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following products: Cisco Prime Data Center Network Manager (DCNM) Version 10.0 and later,
nvd
CVE-2019-15958P2CRITICALCVSS 9.8fixed in 3.4.2≥ 3.5, < 3.5.1+1 more2019-11-26
CVE-2019-15958 [CRITICAL] CWE-20 CVE-2019-15958: A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Ne A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA)
nvd
CVE-2016-1291P2CRITICALCVSS 9.8v1.2v1.2.0.103+10 more2016-04-06
CVE-2016-1291 [CRITICAL] CWE-20 CVE-2016-1291: Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.
nvd
CVE-2016-1289P2CRITICALCVSS 9.8v1.2v1.2.0.103+11 more2016-07-02
CVE-2016-1289 [CRITICAL] CWE-119 CVE-2016-1289: The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information via a crafted HTTP request, as demonstrated by discovering managed-device credentials, aka Bug ID CSCuy10231.
nvd
CVE-2021-1487P2HIGHCVSS 8.8fixed in 3.92021-05-22
CVE-2021-1487 [HIGH] CWE-78 CVE-2021-1487: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Prog A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to insufficient validation of user-supplied input to the web-based management interface. An attacker
nvd
CVE-2016-1442P3HIGHCVSS 8.8v3.0v3.12016-07-07
CVE-2016-1442 [HIGH] CWE-20 CVE-2016-1442: The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authe The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280.
nvd
CVE-2016-6443P3HIGHCVSS 8.8v1.2v1.2.0.103+14 more2016-10-27
CVE-2016-6443 [HIGH] CWE-89 CVE-2016-6443: A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL datab A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries that can cause product instability. More Information: CSCva27038, CSCva28335. Known Affected Releases: 3.1(0.128), 1
nvd
CVE-2019-1824P3HIGHCVSS 8.1fixed in 3.4.12019-05-16
CVE-2019-1824 [HIGH] CWE-89 CVE-2019-1824: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this
nvd
CVE-2019-1825P3HIGHCVSS 8.1fixed in 3.4.12019-05-16
CVE-2019-1825 [HIGH] CWE-89 CVE-2019-1825: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this
nvd
CVE-2016-1408P3HIGHCVSS 8.8v1.2v1.2.0.103+13 more2016-07-02
CVE-2016-1408 [HIGH] CWE-20 CVE-2016-1408: Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2 Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.
nvd
CVE-2014-0679P3CRITICALCVSS 9.0v1.2v1.2.1+4 more2014-02-27
CVE-2014-0679 [CRITICAL] CWE-20 CVE-2014-0679: Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0. Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to execute arbitrary commands with root privileges via an unspecified URL, aka Bug ID CSCum71308.
nvd
CVE-2016-1359P3HIGHCVSS 8.8v3.02016-03-03
CVE-2016-1359 [HIGH] CWE-20 CVE-2016-1359: Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a cra Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewing of a log file, aka Bug ID CSCuw81494.
nvd
CVE-2019-1823P3HIGHCVSS 7.2fixed in 3.4.12019-05-16
CVE-2019-1823 [HIGH] CWE-20 CVE-2019-1823: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
nvd
CVE-2019-1822P3HIGHCVSS 7.2fixed in 3.4.12019-05-16
CVE-2019-1822 [HIGH] CWE-20 CVE-2019-1822: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
nvd
CVE-2017-6662P3HIGHCVSS 8.0v1.2v1.2.0.103+20 more2017-06-26
CVE-2017-6662 [HIGH] CWE-20 CVE-2017-6662: A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Progr A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code execution. The attacker must have valid user credentials. The vulnerability is du
nvd
CVE-2023-20258P3HIGHCVSS 7.2fixed in 3.10.4v3.10.42024-01-17
CVE-2023-20258 [HIGH] CVE-2023-20258: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an a A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected application. An attacker could exploit this vulnerability by uploading a
nvd
CVE-2016-1406P3HIGHCVSS 8.8v1.2v1.2.0.103+12 more2016-05-25
CVE-2016-1406 [HIGH] CWE-284 CVE-2016-1406: The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Networ The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.
nvd
Cisco Prime Infrastructure vulnerabilities | cvebase