Cisco Prime Infrastructure vulnerabilities

82 known vulnerabilities affecting cisco/prime_infrastructure.

Total CVEs
82
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH15MEDIUM58LOW2

Vulnerabilities

Page 2 of 5
CVE-2023-20205MEDIUMCVSS 5.4fixed in 3.10.42023-08-16
CVE-2023-20205 [MEDIUM] CWE-79 CVE-2023-20205: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These vulnerabilities are due to insufficient vali
nvd
CVE-2023-20129MEDIUMCVSS 6.5≤ 3.7≥ 3.10, < 3.10.2+4 more2023-04-05
CVE-2023-20129 [MEDIUM] CWE-27 CVE-2023-20129: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2023-20127MEDIUMCVSS 6.5≤ 3.7≥ 3.10, < 3.10.2+4 more2023-04-05
CVE-2023-20127 [MEDIUM] CWE-27 CVE-2023-20127: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2023-20130MEDIUMCVSS 6.5≤ 3.7≥ 3.10, < 3.10.2+4 more2023-04-05
CVE-2023-20130 [MEDIUM] CWE-27 CVE-2023-20130: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2023-20121MEDIUMCVSS 6.7fixed in 3.10.42023-04-05
CVE-2023-20121 [MEDIUM] CWE-77 CVE-2023-20121: Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more information about these vulnerabil
nvd
CVE-2023-20068MEDIUMCVSS 6.1fixed in 3.10.32023-04-05
CVE-2023-20068 [MEDIUM] CWE-79 CVE-2023-20068: A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could a A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could expl
nvd
CVE-2023-20131MEDIUMCVSS 5.4≤ 3.7≥ 3.10, < 3.10.2+4 more2023-04-05
CVE-2023-20131 [MEDIUM] CWE-27 CVE-2023-20131: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2023-20069MEDIUMCVSS 5.4fixed in 3.10.32023-03-03
CVE-2023-20069 [MEDIUM] CWE-79 CVE-2023-20069: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user
nvd
CVE-2022-20659MEDIUMCVSS 6.1fixed in 3.102022-02-17
CVE-2022-20659 [MEDIUM] CWE-79 CVE-2022-20659: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interf
nvd
CVE-2021-34784MEDIUMCVSS 5.4fixed in 3.102021-11-04
CVE-2021-34784 [MEDIUM] CWE-79 CVE-2021-34784: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability exists because
nvd
CVE-2021-34733MEDIUMCVSS 5.5fixed in 3.82021-09-02
CVE-2021-34733 [MEDIUM] CWE-522 CVE-2021-34733: A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists because sensitive information is not sufficiently secured when it is stored. A
nvd
CVE-2021-1487HIGHCVSS 8.8fixed in 3.92021-05-22
CVE-2021-1487 [HIGH] CWE-78 CVE-2021-1487: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Prog A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to insufficient validation of user-supplied input to the web-based management interface. An attacker
nvd
CVE-2021-1306LOWCVSS 3.4fixed in 3.8.1v3.8.12021-05-22
CVE-2021-1306 [MEDIUM] CWE-73 CVE-2021-1306: A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco I A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and write arbitrary files to the file system. This vulnerability is due to improper validation of parameters that are sent
nvd
CVE-2020-3339MEDIUMCVSS 5.4≤ 3.7.1v3.82020-06-03
CVE-2020-3339 [MEDIUM] CWE-89 CVE-2020-3339: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an a A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and send
nvd
CVE-2019-15958CRITICALCVSS 9.8fixed in 3.4.2≥ 3.5, < 3.5.1+1 more2019-11-26
CVE-2019-15958 [CRITICAL] CWE-20 CVE-2019-15958: A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Ne A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA)
nvd
CVE-2019-12713MEDIUMCVSS 6.1v3.52019-10-02
CVE-2019-12713 [MEDIUM] CWE-79 CVE-2019-12713: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an u A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based ma
nvd
CVE-2019-12712MEDIUMCVSS 6.1v3.72019-10-02
CVE-2019-12712 [MEDIUM] CWE-79 CVE-2019-12712: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an u A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input in multiple section
nvd
CVE-2019-1906MEDIUMCVSS 6.5v3.62019-06-20
CVE-2019-1906 [MEDIUM] CWE-264 CVE-2019-1906: A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authe A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by manipulating requests sent t
nvd
CVE-2019-1821CRITICALCVSS 9.8PoCfixed in 3.4.12019-05-16
CVE-2019-1821 [HIGH] CWE-20 CVE-2019-1821: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
nvd
CVE-2019-1824HIGHCVSS 8.1fixed in 3.4.12019-05-16
CVE-2019-1824 [HIGH] CWE-89 CVE-2019-1824: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this
nvd