PT-2022-1421 · Cisco · Cisco Prime Infrastructure+1

Andreas Finstad

+1

·

Published

2022-01-12

·

Updated

2024-11-18

·

CVE-2022-20657

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (affected versions not specified)
Description A vulnerability in the web-based management interface could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This issue exists due to the interface not properly validating user-supplied input. An attacker could exploit this by persuading a user to click a crafted link, potentially allowing the execution of arbitrary script code or access to sensitive browser-based information.
Recommendations For Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager, update to a version that includes the software updates released by Cisco to address this issue. As a temporary workaround, consider restricting access to the web-based management interface until a patch is applied. Avoid using the interface with untrusted input until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-00522
CVE-2022-20657

Affected Products

Cisco Evolved Programmable Network Manager
Cisco Prime Infrastructure