CVE-2023-20129

EUVD-2023-24308
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see the Details section of this advisory.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ciscoCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
ciscoprime_infrastructure
𝑥
≤ 3.7
ciscoprime_infrastructure
3.10 ≤
𝑥
< 3.10.2
ciscoprime_infrastructure
3.8
ciscoprime_infrastructure
3.8.1
ciscoprime_infrastructure
3.9
ciscoprime_infrastructure
3.9.1
ciscoevolved_programmable_network_manager
𝑥
< 5.0.2.5
ciscoevolved_programmable_network_manager
5.1 ≤
𝑥
< 5.1.4.2
ciscoevolved_programmable_network_manager
6.0 ≤
𝑥
< 6.0.2.1
ciscoevolved_programmable_network_manager
6.1 ≤
𝑥
< 6.1.1.1
𝑥
= Vulnerable software versions