CVE-2023-20130

Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see the Details section of this advisory.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ciscoCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
VendorProductVersion
ciscoprime_infrastructure
𝑥
≤ 3.7
ciscoprime_infrastructure
3.10 ≤
𝑥
< 3.10.2
ciscoprime_infrastructure
3.8
ciscoprime_infrastructure
3.8.1
ciscoprime_infrastructure
3.9
ciscoprime_infrastructure
3.9.1
ciscoevolved_programmable_network_manager
𝑥
< 5.0.2.5
ciscoevolved_programmable_network_manager
5.1 ≤
𝑥
< 5.1.4.2
ciscoevolved_programmable_network_manager
6.0 ≤
𝑥
< 6.0.2.1
ciscoevolved_programmable_network_manager
6.1 ≤
𝑥
< 6.1.1.1
𝑥
= Vulnerable software versions