Cisco PI and EPNMWeb-Based Management Interface Vulnerability
CVE-2022-20657

6.1MEDIUM

Key Information:

Summary

A cross-site scripting (XSS) vulnerability exists in the web-based management interface of Cisco Prime Infrastructure and Cisco Enhanced Packet Network Manager. This issue arises when the interface fails to properly validate user-supplied input, allowing potential exploitation by remote attackers. By convincing an interface user to click a crafted link, an attacker could execute arbitrary script code in the context of the user’s session. This could potentially allow attackers to access sensitive data and browser-based information pertaining to the affected device. Cisco has addressed this vulnerability through software updates, without any viable workarounds available.

Affected Version(s)

Cisco Evolved Programmable Network Manager (EPNM) 3.0.1

Cisco Evolved Programmable Network Manager (EPNM) 3.1.2

Cisco Evolved Programmable Network Manager (EPNM) 1.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.