Cisco Evolved Programmable Network Manager
cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*
- <= 6.1
- <= 7.1
- <= 8.0
A stored cross-site scripting vulnerability has been identified in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. This vulnerability allows an unauthenticated, remote attacker to inject malicious scripts into specific pages of the interface. The injected scripts could be executed in the context of the user's session, potentially accessing sensitive browser-based information.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the affected user interface.
Cisco has released software updates to address this vulnerability. For Cisco EPNM, users should upgrade to version 6.1.2.3, 7.1.3.1, or 8.0.0.1. For Cisco Prime Infrastructure, users should upgrade to version 3.10.6.1. Instructions for upgrading can be found in the Cisco Security Vulnerability Policy.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.