VendorsCiscoprime_infrastructureall versions
Vulnerabilities

Cisco Prime Infrastructure

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

89CVEs
CVE-2019-1821
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Published 2019-05-16 · Modified
10.02 PoCEPSS 0.981
CVE-2018-0258
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following products: Cisco Prime Data Center Network Manager (DCNM) Version 10.0 and later, and Cisco Prime Infrastructure (PI) All versions. Cisco Bug IDs: CSCvf32411, CSCvf81727.
Published 2018-05-02 · Modified
10.0EPSS 0.482
CVE-2016-1289
The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information via a crafted HTTP request, as demonstrated by discovering managed-device credentials, aka Bug ID CSCuy10231.
Published 2016-07-02 · Modified
10.0EPSS 0.062
CVE-2019-15958
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
Published 2019-11-26 · Modified
10.0EPSS 0.033
CVE-2018-15379
Cisco Prime Infrastructure Arbitrary File Upload and Command Execution Vulnerability
Published 2018-10-05 · Modified
9.81 PoCEPSS 0.862
CVE-2016-1291
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.
Published 2016-04-06 · Modified
9.8EPSS 0.068
CVE-2019-1823
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Published 2019-05-16 · Modified
9.0EPSS 0.044
CVE-2019-1822
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Published 2019-05-16 · Modified
9.0EPSS 0.044
CVE-2016-1442
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280.
Published 2016-07-07 · Modified
9.0EPSS 0.032
CVE-2021-1487
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Command Injection Vulnerability
Published 2021-05-22 · Modified
9.0EPSS 0.021
CVE-2014-0679
Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to execute arbitrary commands with root privileges via an unspecified URL, aka Bug ID CSCum71308.
Published 2014-02-27 · Modified
9.0EPSS 0.021
CVE-2016-6443
A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries that can cause product instability. More Information: CSCva27038, CSCva28335. Known Affected Releases: 3.1(0.128), 1.2(400), 2.0(1.0.34A).
Published 2016-10-27 · Modified
8.8EPSS 0.030
CVE-2016-1408
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.
Published 2016-07-02 · Modified
8.8EPSS 0.025
CVE-2016-1359
Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewing of a log file, aka Bug ID CSCuw81494.
Published 2016-03-03 · Modified
8.8EPSS 0.022
CVE-2016-1406
The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.
Published 2016-05-25 · Modified
8.8EPSS 0.016
CVE-2019-1824
Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL Injection Vulnerabilities
Published 2019-05-16 · Modified
8.1EPSS 0.019
CVE-2019-1825
Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL Injection Vulnerabilities
Published 2019-05-16 · Modified
8.1EPSS 0.019
CVE-2016-1290
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.
Published 2016-04-06 · Modified
8.1EPSS 0.015
CVE-2017-6662
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code execution. The attacker must have valid user credentials. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by convincing the administrator of an affected system to import a crafted XML file with malicious entries which could allow the attacker to read and write files and execute remote code within the application, aka XML Injection. Cisco Prime Infrastructure software releases 1.1 through 3.1.6 are vulnerable. Cisco EPNM software releases 1.2, 2.0, and 2.1 are vulnerable. Cisco Bug IDs: CSCvc23894 CSCvc49561.
Published 2017-06-26 · Modified
8.0EPSS 0.024
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2019-1659
Cisco Prime Infrastructure Certificate Validation Vulnerability
Published 2019-02-21 · Modified
7.4EPSS 0.008
CVE-2023-20258
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected application. An attacker could exploit this vulnerability by uploading a document containing malicious serialized Java objects to be processed by the affected application. A successful exploit could allow the attacker to cause the application to execute arbitrary commands.
Published 2024-01-17 · Modified
7.2EPSS 0.007
CVE-2015-6262
Cross-site request forgery (CSRF) vulnerability in Cisco Prime Infrastructure 1.2(0.103) and 2.0(0.0) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCum49054 and CSCum49059.
Published 2015-08-25 · Modified
6.8EPSS 0.010
CVE-2014-2152
Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun21868.
Published 2015-02-12 · Modified
6.8EPSS 0.010
CVE-2013-1153
Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCue84676.
Published 2013-03-07 · Modified
6.8EPSS 0.006
CVE-2023-20121
Cisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection Vulnerabilities
Published 2023-04-05 · Modified
6.7EPSS 0.002
CVE-2023-20260
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing of command line arguments to application scripts. An attacker could exploit this vulnerability by issuing a command on the CLI with malicious options. A successful exploit could allow the attacker to gain the escalated privileges of the root user on the underlying operating system.
Published 2024-01-17 · Modified
6.7EPSS 0.002
CVE-2019-1818
Cisco Prime Infrastructure and Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2019-05-16 · Modified
6.5EPSS 0.136
CVE-2019-1819
Cisco Prime Infrastructure and Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2019-05-16 · Modified
6.5EPSS 0.136
CVE-2019-1820
Cisco Prime Infrastructure and Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2019-05-16 · Modified
6.5EPSS 0.136
CVE-2017-3884
A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to access sensitive data. The attacker does not need administrator credentials and could use this information to conduct additional reconnaissance attacks. More Information: CSCvc60031 (Fixed) CSCvc60041 (Fixed) CSCvc60095 (Open) CSCvc60102 (Open). Known Affected Releases: 2.2 2.2(3) 3.0 3.1(0.0) 3.1(0.128) 3.1(4.0) 3.1(5.0) 3.2(0.0) 2.0(4.0.45D).
Published 2017-04-07 · Modified
6.5EPSS 0.021
CVE-2022-20656
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2024-11-15 · Analyzed
6.5EPSS 0.017
CVE-2019-1906
Cisco Prime Infrastructure Virtual Domain Privilege Escalation Vulnerability
Published 2019-06-20 · Modified
6.5EPSS 0.013
CVE-2023-20127
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.009
CVE-2023-20129
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.009
CVE-2023-20131
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.006
CVE-2023-20271
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain and modify sensitive information that is stored in the underlying database.
Published 2024-01-17 · Modified
6.5EPSS 0.005
CVE-2025-20269
Cisco Evolved Programmable Network Manager and Prime Infrastructure Arbitrary File Download Vulnerability
Published 2025-08-20 · Analyzed
6.5EPSS 0.004
CVE-2023-20130
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.004
CVE-2025-20270
Cisco Evolved Programmable Network Manager Information Disclosure Vulnerability
Published 2025-09-03 · Analyzed
6.5EPSS 0.003
1 / 3Next →