Cisco PI and EPNMWeb-Based Management Interface Vulnerability
CVE-2022-20657
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 15 November 2024
What is CVE-2022-20657?
A cross-site scripting (XSS) vulnerability exists in the web-based management interface of Cisco Prime Infrastructure and Cisco Enhanced Packet Network Manager. This issue arises when the interface fails to properly validate user-supplied input, allowing potential exploitation by remote attackers. By convincing an interface user to click a crafted link, an attacker could execute arbitrary script code in the context of the user’s session. This could potentially allow attackers to access sensitive data and browser-based information pertaining to the affected device. Cisco has addressed this vulnerability through software updates, without any viable workarounds available.
Affected Version(s)
Cisco Evolved Programmable Network Manager (EPNM) 3.0.1
Cisco Evolved Programmable Network Manager (EPNM) 3.1.2
Cisco Evolved Programmable Network Manager (EPNM) 1.2