Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Vulnerabilities

cisco-sa-pi-epnm-wkZJeyeq · Medium · Published · Updated

Multiple vulnerabilities in Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an attacker to conduct cross-site scripting (XSS) attacks, execute arbitrary commands, perform SQL injection attacks, or gain elevated privileges on an affected system.  Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. For more information about these vulnerabilities, see the Details section of this advisory. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-epnm-wkZJeyeq

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address these vulnerabilities.

CVEsCVE-2023-20257, CVE-2023-20258, CVE-2023-20260, CVE-2023-20271
Cisco Bug IDsCSCwf81870, CSCwf83565, CSCwf81859, CSCwf81865, CSCwf83560, CSCwf81862, CSCwf83557
CVSS ScoreBase 4.8
Base 4.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N/E:X/RL:X/RC:X
Base 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N/E:X/RL:X/RC:X
Base 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N/E:X/RL:X/RC:X
Base 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Prime Infrastructure, Cisco Evolved Programmable Network Manager (EPNM)

Related Products

Product CVE Evidence
Cisco Prime Infrastructure CVE-2023-20271 Cisco OpenVuln
Cisco Prime Infrastructure CVE-2023-20260 Cisco OpenVuln
Cisco Prime Infrastructure CVE-2023-20258 Cisco OpenVuln
Cisco Prime Infrastructure CVE-2023-20257 Cisco OpenVuln
Cisco Evolved Programmable Network Manager (EPNM) CVE-2023-20271 Cisco OpenVuln
Cisco Evolved Programmable Network Manager (EPNM) CVE-2023-20260 Cisco OpenVuln
Cisco Evolved Programmable Network Manager (EPNM) CVE-2023-20258 Cisco OpenVuln
Cisco Evolved Programmable Network Manager (EPNM) CVE-2023-20257 Cisco OpenVuln