QID 730779

Date Published: 2023-04-12

QID 730779: Cisco Prime Infrastructure Multiple Security Vulnerabilities (cisco-sa-pi-epnm-eRPWAXLe)

Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.

Affected Versions:
Cisco Prime Infrastructure versions 3.7 and earlier
Cisco Prime Infrastructure version 3.8
Cisco Prime Infrastructure version 3.9
Cisco Prime Infrastructure version from 3.10 prior to 3.10.2

QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable Cisco Prime Infrastructure version retrieved via a GET request to a "webacs/js/xmp/nls/xmp.js"

Successful exploitation of this vulnerability may allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-pi-epnm-eRPWAXLe for more information.

    CVEs related to QID 730779

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-pi-epnm-eRPWAXLe URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-epnm-eRPWAXLe