Cisco Prime Infrastructure vulnerabilities
83 known vulnerabilities affecting cisco/prime_infrastructure.
Total CVEs
83
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH15MEDIUM59LOW2
Vulnerabilities
Page 4 of 5
CVE-2017-6782P4MEDIUMCVSS 5.4v3.2\(0.0\)2017-08-17
CVE-2017-6782 [MEDIUM] CWE-94 CVE-2017-6782: A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an aut
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application. The vulnerability is due to improper sanitization of parameter values by the affected application. An attacker could exploit this vulnerability by injecting ma
nvd
CVE-2021-34733P4MEDIUMCVSS 5.5fixed in 3.82021-09-02
CVE-2021-34733 [MEDIUM] CWE-522 CVE-2021-34733: A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN
A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists because sensitive information is not sufficiently secured when it is stored. A
nvd
CVE-2023-20069P4MEDIUMCVSS 5.4fixed in 3.10.32023-03-03
CVE-2023-20069 [MEDIUM] CWE-79 CVE-2023-20069: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user
nvd
CVE-2024-20514P4MEDIUMCVSS 5.4fixed in 3.10.62024-11-06
CVE-2024-20514 [MEDIUM] CWE-79 CVE-2024-20514: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability exists because the web-based management interf
nvd
CVE-2025-20272P4MEDIUMCVSS 4.3fixed in 3.10.6v3.10.6+1 more2025-07-16
CVE-2025-20272 [MEDIUM] CWE-89 CVE-2025-20272: A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmabl
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability b
nvd
CVE-2023-20130P4MEDIUMCVSS 6.5≤ 3.7≥ 3.10, < 3.10.2+4 more2023-04-05
CVE-2023-20130 [MEDIUM] CWE-27 CVE-2023-20130: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2017-6699P4MEDIUMCVSS 6.1v3.1v3.1\(0.128\)+1 more2017-07-04
CVE-2017-6699 [MEDIUM] CWE-79 CVE-2017-6699: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc24616 CSCvc35
nvd
CVE-2018-0482P4MEDIUMCVSS 5.4v3.5\(0.0\)2019-01-10
CVE-2018-0482 [MEDIUM] CWE-79 CVE-2018-0482: A vulnerability in the web-based management interface of Cisco Prime Network Control System could al
A vulnerability in the web-based management interface of Cisco Prime Network Control System could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management
nvd
CVE-2021-34784P4MEDIUMCVSS 5.4fixed in 3.102021-11-04
CVE-2021-34784 [MEDIUM] CWE-79 CVE-2021-34784: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability exists because
nvd
CVE-2015-6434P4MEDIUMCVSS 6.1v2.2\(2\)2016-01-08
CVE-2015-6434 [MEDIUM] CWE-79 CVE-2015-6434: Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier
Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCux64856.
nvd
CVE-2015-6332P4MEDIUMCVSS 5.0v2.22015-10-13
CVE-2015-6332 [MEDIUM] CWE-399 CVE-2015-6332: Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by
Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by sending many SSL renegotiation requests, aka Bug ID CSCuv56830.
nvd
CVE-2023-20131P4MEDIUMCVSS 5.4≤ 3.7≥ 3.10, < 3.10.2+4 more2023-04-05
CVE-2023-20131 [MEDIUM] CWE-27 CVE-2023-20131: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2026-20075P4MEDIUMCVSS 4.8≤ 3.9≥ 3.10.0, ≤ 3.10.62026-01-15
CVE-2026-20075 [MEDIUM] CWE-79 CVE-2026-20075: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.
This vulnerability exists because the web-based management i
nvd
CVE-2026-20111P4MEDIUMCVSS 4.8fixed in 3.10.6v3.10.6+1 more2026-02-04
CVE-2026-20111 [MEDIUM] CWE-798 CVE-2026-20111: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an a
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.
This vulnerability exists because the web-based management interface does not properly validate user-supplied in
nvd
CVE-2025-20203P4MEDIUMCVSS 4.8v2.0.0v2.0.10+101 more2025-04-02
CVE-2025-20203 [MEDIUM] CWE-79 CVE-2025-20203: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.
The vulnerability exists because the web-based management int
nvd
CVE-2025-20280P4MEDIUMCVSS 4.8≤ 3.9≥ 3.10, ≤ 3.10.62025-09-03
CVE-2025-20280 [MEDIUM] CWE-79 CVE-2025-20280: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.
This vulnerability exists because the web-based management i
nvd
CVE-2023-20257P4MEDIUMCVSS 4.8fixed in 3.10.4v3.10.42024-01-17
CVE-2023-20257 [MEDIUM] CWE-80 CVE-2023-20257: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an a
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by submitting malicious i
nvd
CVE-2018-15432P4MEDIUMCVSS 4.3v3.22018-10-05
CVE-2018-15432 [MEDIUM] CWE-200 CVE-2018-15432: A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authentic
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. A succes
nvd
CVE-2018-15433P4MEDIUMCVSS 4.3v3.22018-10-05
CVE-2018-15433 [MEDIUM] CWE-200 CVE-2018-15433: A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authentic
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. A succes
nvd
CVE-2014-2147P4MEDIUMCVSS 4.3≤ 2.12015-02-12
CVE-2014-2147 [MEDIUM] CWE-20 CVE-2014-2147: The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IF
The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuj42444.
nvd