6.1
CVE-2022-20657
- EPSS 0.24%
- Veröffentlicht 15.11.2024 16:15:21
- Zuletzt bearbeitet 31.07.2025 15:05:55
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Prime Infrastructure Version2.0.0
Cisco ≫ Prime Infrastructure Version2.1
Cisco ≫ Prime Infrastructure Version2.2
Cisco ≫ Prime Infrastructure Version3.0.0
Cisco ≫ Prime Infrastructure Version3.1.0
Cisco ≫ Prime Infrastructure Version3.1.5
Cisco ≫ Prime Infrastructure Version3.2
Cisco ≫ Prime Infrastructure Version3.2.0-fips
Cisco ≫ Prime Infrastructure Version3.3.0
Cisco ≫ Prime Infrastructure Version3.4.0
Cisco ≫ Prime Infrastructure Version3.5.0
Cisco ≫ Prime Infrastructure Version3.6.0
Cisco ≫ Prime Infrastructure Version3.7.0
Cisco ≫ Prime Infrastructure Version3.8.0
Cisco ≫ Prime Infrastructure Version3.9.0
Cisco ≫ Evolved Programmable Network Manager Version1.1
Cisco ≫ Evolved Programmable Network Manager Version1.2
Cisco ≫ Evolved Programmable Network Manager Version2.0
Cisco ≫ Evolved Programmable Network Manager Version2.1
Cisco ≫ Evolved Programmable Network Manager Version2.2
Cisco ≫ Evolved Programmable Network Manager Version3.0
Cisco ≫ Evolved Programmable Network Manager Version3.0.1
Cisco ≫ Evolved Programmable Network Manager Version3.0.2
Cisco ≫ Evolved Programmable Network Manager Version3.0.3
Cisco ≫ Evolved Programmable Network Manager Version3.1
Cisco ≫ Evolved Programmable Network Manager Version3.1.1
Cisco ≫ Evolved Programmable Network Manager Version3.1.2
Cisco ≫ Evolved Programmable Network Manager Version3.1.3
Cisco ≫ Evolved Programmable Network Manager Version4.0
Cisco ≫ Evolved Programmable Network Manager Version4.0.1
Cisco ≫ Evolved Programmable Network Manager Version4.0.2
Cisco ≫ Evolved Programmable Network Manager Version4.0.3
Cisco ≫ Evolved Programmable Network Manager Version4.1
Cisco ≫ Evolved Programmable Network Manager Version4.1.1
Cisco ≫ Evolved Programmable Network Manager Version5.0
Cisco ≫ Evolved Programmable Network Manager Version5.0.1
Cisco ≫ Evolved Programmable Network Manager Version5.0.2
Cisco ≫ Evolved Programmable Network Manager Version5.1
Cisco ≫ Evolved Programmable Network Manager Version5.1.1
Cisco ≫ Evolved Programmable Network Manager Version5.1.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.474 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@cisco.com | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.