Cisco Evolved Programmable Network Manager
cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*
- <= 8.0
- >= 8.1, < 8.1.1
A vulnerability exists in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. It allows an unauthenticated, remote attacker to redirect a user to a malicious web page. This issue arises from improper input validation of parameters in HTTP requests. An attacker could exploit this vulnerability by intercepting and modifying a user's HTTP request, leading to the redirection.
Exploitation of this vulnerability could result in an open redirect, allowing attackers to send users to malicious websites.
Users are advised to upgrade to Cisco EPNM version 8.1.1 or Cisco Prime Infrastructure version 3.10.6 Security Update 2. Instructions for upgrading can be found on the Cisco Support and Downloads page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.