- EPSS 30.71%
- Published 02.05.2018 22:29:00
- Last modified 21.11.2024 03:37:49
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability ...
CVE-2018-0097
- EPSS 0.25%
- Published 18.01.2018 06:29:00
- Last modified 21.11.2024 03:37:30
A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of the paramete...
CVE-2018-0096
- EPSS 0.25%
- Published 18.01.2018 06:29:00
- Last modified 21.11.2024 03:37:30
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to perform a privilege escalation in which one virtual domain user can view and modify another virtual d...
CVE-2017-6699
- EPSS 0.35%
- Published 04.07.2017 00:29:00
- Last modified 20.04.2025 01:37:25
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against ...
- EPSS 0.95%
- Published 26.06.2017 07:29:00
- Last modified 20.04.2025 01:37:25
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as wel...
CVE-2017-3848
- EPSS 0.29%
- Published 07.04.2017 17:59:00
- Last modified 20.04.2025 01:37:25
A vulnerability in the HTTP web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected system. More I...
CVE-2017-3884
- EPSS 0.23%
- Published 07.04.2017 17:59:00
- Last modified 20.04.2025 01:37:25
A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to access sensitive data. The attacker does not need administrator credentials and c...
CVE-2016-6443
- EPSS 1.87%
- Published 27.10.2016 21:59:14
- Last modified 12.04.2025 10:46:40
A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries that can c...
- EPSS 0.7%
- Published 07.07.2016 14:59:03
- Last modified 12.04.2025 10:46:40
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280.
CVE-2016-1408
- EPSS 0.35%
- Published 02.07.2016 14:59:07
- Last modified 12.04.2025 10:46:40
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.