QID 730779
Date Published: 2023-04-12
QID 730779: Cisco Prime Infrastructure Multiple Security Vulnerabilities (cisco-sa-pi-epnm-eRPWAXLe)
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.
Affected Versions:
Cisco Prime Infrastructure versions 3.7 and earlier
Cisco Prime Infrastructure version 3.8
Cisco Prime Infrastructure version 3.9
Cisco Prime Infrastructure version from 3.10 prior to 3.10.2
QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable Cisco Prime Infrastructure version retrieved via a GET request to a "webacs/js/xmp/nls/xmp.js"
Successful exploitation of this vulnerability may allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.
Customers are advised to refer to cisco-sa-pi-epnm-eRPWAXLe for more information.
- cisco-sa-pi-epnm-eRPWAXLe -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-epnm-eRPWAXLe
CVEs related to QID 730779
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-pi-epnm-eRPWAXLe |
|