Cisco

Prime Infrastructure

76 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.66%
  • Published 02.07.2016 14:59:06
  • Last modified 12.04.2025 10:46:40

The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information via a crafted HTTP request, as demonstrated by disc...

  • EPSS 0.3%
  • Published 25.05.2016 01:59:09
  • Last modified 12.04.2025 10:46:40

The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain ...

  • EPSS 2.32%
  • Published 06.04.2016 23:59:11
  • Last modified 12.04.2025 10:46:40

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.

  • EPSS 0.17%
  • Published 06.04.2016 23:59:10
  • Last modified 12.04.2025 10:46:40

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsiste...

  • EPSS 0.51%
  • Published 03.03.2016 22:59:15
  • Last modified 12.04.2025 10:46:40

Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewing of a log file, aka Bug ID CSCuw81494.

  • EPSS 0.49%
  • Published 03.03.2016 22:59:15
  • Last modified 12.04.2025 10:46:40

Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to...

  • EPSS 0.46%
  • Published 13.10.2015 00:59:02
  • Last modified 12.04.2025 10:46:40

Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by sending many SSL renegotiation requests, aka Bug ID CSCuv56830.

  • EPSS 0.11%
  • Published 25.08.2015 01:59:10
  • Last modified 12.04.2025 10:46:40

Cross-site request forgery (CSRF) vulnerability in Cisco Prime Infrastructure 1.2(0.103) and 2.0(0.0) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCum49054 and CSCum49059.

  • EPSS 0.17%
  • Published 22.08.2015 17:59:00
  • Last modified 12.04.2025 10:46:40

Cisco Prime Infrastructure (PI) 1.4(0.45) and earlier, when AAA authentication is used, allows remote authenticated users to bypass intended access restrictions via a username with a modified composition of lowercase and uppercase characters, aka Bug...

  • EPSS 0.26%
  • Published 12.02.2015 01:59:17
  • Last modified 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in INSERT pages in Cisco Prime Infrastructure allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun21869.