CVE-2023-20130: Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What are the affected software versions for CVE-2023-20130?
The affected software versions for CVE-2023-20130 are Cisco Prime Infrastructure 3.7 to 3.10.2, Cisco Prime Infrastructure 3.8, Cisco Prime Infrastructure 3.8.1, Cisco Prime Infrastructure 3.9, and Cisco Evolved Programmable Network Manager 5.0.2.5 to 6.1.1.1.
What is the severity level of CVE-2023-20130?
The severity level of CVE-2023-20130 is medium with a CVSS score of 6.5.
What are the vulnerabilities in CVE-2023-20130?
The vulnerabilities in CVE-2023-20130 include obtaining privileged information, cross-site scripting (XSS), and cross-site request forgery (CSRF) attacks.
How can a remote attacker exploit CVE-2023-20130?
A remote attacker can exploit CVE-2023-20130 by obtaining privileged information and conducting cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.
Where can I find more information about CVE-2023-20130?
You can find more information about CVE-2023-20130 on the Cisco Security Advisory page: <a href='https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-epnm-eRPWAXLe'>Cisco Security Advisory</a>.