QID 730177
Date Published: 2021-09-02
QID 730177: Cisco Prime Infrastructure Information Disclosure Vulnerability (cisco-sa-prime-info-disc-nTU9FJ2)
A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager
could allow an authenticated, local attacker to access sensitive information
stored on the underlying file system of an affected system.
Affected Products
Cisco Prime Infrastructure releases earlier than Release 3.8 and Cisco EPN Manager releases earlier than Release 5.0.
Note: No Support for Cisco EPN Manager
QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable Cisco Prime Infrastructure version retrieved via a GET request to a "webacs/js/xmp/nls/xmp.js"
A successful exploit could allow the attacker to create forged authentication requests and gain unauthorized access to the affected system.
Customers are advised to refer to cisco-sa-prime-info-disc-nTU9FJ2 for more information.
- cisco-sa-prime-info-disc-nTU9FJ2 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-prime-info-disc-nTU9FJ2
CVEs related to QID 730177
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-prime-info-disc-nTU9FJ2 |
|