VendorsCiscoprime_infrastructureany version
Vulnerabilities

Cisco Prime Infrastructure any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2019-1821
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Published 2019-05-16 · Modified
10.02 PoCEPSS 0.981
CVE-2019-15958
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
Published 2019-11-26 · Modified
10.0EPSS 0.033
CVE-2019-1823
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Published 2019-05-16 · Modified
9.0EPSS 0.044
CVE-2019-1822
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Published 2019-05-16 · Modified
9.0EPSS 0.044
CVE-2021-1487
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Command Injection Vulnerability
Published 2021-05-22 · Modified
9.0EPSS 0.021
CVE-2019-1824
Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL Injection Vulnerabilities
Published 2019-05-16 · Modified
8.1EPSS 0.019
CVE-2019-1825
Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL Injection Vulnerabilities
Published 2019-05-16 · Modified
8.1EPSS 0.019
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2019-1659
Cisco Prime Infrastructure Certificate Validation Vulnerability
Published 2019-02-21 · Modified
7.4EPSS 0.008
CVE-2023-20258
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected application. An attacker could exploit this vulnerability by uploading a document containing malicious serialized Java objects to be processed by the affected application. A successful exploit could allow the attacker to cause the application to execute arbitrary commands.
Published 2024-01-17 · Modified
7.2EPSS 0.007
CVE-2014-2152
Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun21868.
Published 2015-02-12 · Modified
6.8EPSS 0.010
CVE-2013-1153
Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCue84676.
Published 2013-03-07 · Modified
6.8EPSS 0.006
CVE-2023-20121
Cisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection Vulnerabilities
Published 2023-04-05 · Modified
6.7EPSS 0.002
CVE-2023-20260
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing of command line arguments to application scripts. An attacker could exploit this vulnerability by issuing a command on the CLI with malicious options. A successful exploit could allow the attacker to gain the escalated privileges of the root user on the underlying operating system.
Published 2024-01-17 · Modified
6.7EPSS 0.002
CVE-2019-1818
Cisco Prime Infrastructure and Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2019-05-16 · Modified
6.5EPSS 0.136
CVE-2019-1819
Cisco Prime Infrastructure and Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2019-05-16 · Modified
6.5EPSS 0.136
CVE-2019-1820
Cisco Prime Infrastructure and Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2019-05-16 · Modified
6.5EPSS 0.136
CVE-2023-20127
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.009
CVE-2023-20129
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.009
CVE-2023-20131
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.006
CVE-2023-20271
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain and modify sensitive information that is stored in the underlying database.
Published 2024-01-17 · Modified
6.5EPSS 0.005
CVE-2025-20269
Cisco Evolved Programmable Network Manager and Prime Infrastructure Arbitrary File Download Vulnerability
Published 2025-08-20 · Analyzed
6.5EPSS 0.004
CVE-2023-20130
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.004
CVE-2025-20270
Cisco Evolved Programmable Network Manager Information Disclosure Vulnerability
Published 2025-09-03 · Analyzed
6.5EPSS 0.003
CVE-2020-3339
Cisco Prime Infrastructure SQL Injection Vulnerability
Published 2020-06-03 · Modified
6.4EPSS 0.011
CVE-2022-20659
Cisco Prime Infrastructure and Evolved Programmable Network Manager Cross-Site Scripting Vulnerability
Published 2022-02-17 · Modified
6.1EPSS 0.012
CVE-2018-0097
A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by crafting an HTTP request that could cause the web application to redirect the request to a specific malicious URL. This vulnerability is known as an open redirect attack and is used in phishing attacks to get users to visit malicious sites without their knowledge. Cisco Bug IDs: CSCve37646.
Published 2018-01-18 · Modified
6.1EPSS 0.012
CVE-2023-20068
Cisco Prime Infrastructure Reflected Cross-Site Scripting Vulnerability
Published 2023-04-05 · Modified
6.1EPSS 0.005
CVE-2023-20222
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published 2023-08-16 · Modified
6.1EPSS 0.005
CVE-2026-20123
Cisco Prime Infrastructure and Evolved Programmable Network Manager Open Redirect Vulnerability
Published 2026-02-04 · Analyzed
6.1EPSS 0.002
CVE-2021-34733
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Information Disclosure Vulnerability
Published 2021-09-02 · Modified
5.5EPSS 0.002
CVE-2021-34784
Cisco Prime Infrastructure and Evolved Programmable Network Manager Stored Cross-Site Scripting Vulnerability
Published 2021-11-04 · Modified
5.4EPSS 0.006
CVE-2023-20069
Cisco Prime Infrastructure and Evolved Programmable Network Manager Stored Cross-Site Scripting Vulnerability
Published 2023-03-03 · Modified
5.4EPSS 0.005
CVE-2023-20203
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by persuading a user of an affected interface to view a page containing malicious HTML or script content. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid credentials to access the web-based management interface of the affected device.
Published 2023-08-16 · Modified
5.4EPSS 0.004
CVE-2023-20205
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by persuading a user of an affected interface to view a page containing malicious HTML or script content. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid credentials to access the web-based management interface of the affected device.
Published 2023-08-16 · Modified
5.4EPSS 0.004
CVE-2023-20201
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by persuading a user of an affected interface to view a page containing malicious HTML or script content. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid credentials to access the web-based management interface of the affected device.
Published 2023-08-16 · Modified
5.4EPSS 0.004
CVE-2024-20514
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability
Published 2024-11-06 · Analyzed
5.4EPSS 0.003
CVE-2023-20257
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by submitting malicious input containing script or HTML content within requests that would stored within the application interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks against other users of the affected application.
Published 2024-01-17 · Modified
4.8EPSS 0.004
CVE-2026-20075
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability
Published 2026-01-15 · Analyzed
4.8EPSS 0.003
CVE-2025-20280
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability
Published 2025-09-03 · Analyzed
4.8EPSS 0.002
1 / 2Next →