First published: Wed Apr 05 2023(Updated: )
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Infrastructure | <=3.7 | |
Cisco Prime Infrastructure | >=3.10<3.10.2 | |
Cisco Prime Infrastructure | =3.8 | |
Cisco Prime Infrastructure | =3.8.1 | |
Cisco Prime Infrastructure | =3.9 | |
Cisco Prime Infrastructure | =3.9.1 | |
Cisco Evolved Programmable Network Manager | <5.0.2.5 | |
Cisco Evolved Programmable Network Manager | >=5.1<5.1.4.2 | |
Cisco Evolved Programmable Network Manager | >=6.0<6.0.2.1 | |
Cisco Evolved Programmable Network Manager | >=6.1<6.1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.
The severity of CVE-2023-20129 is medium with a CVSS score of 6.5.
Apply the necessary security patches provided by Cisco to mitigate the vulnerabilities in Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager.
You can find more information about CVE-2023-20129 in the Cisco Security Advisory at the following link: [link](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-epnm-eRPWAXLe).