Information disclosure in Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager - CVE-2023-20129
Published: April 6, 2023
Vulnerability identifier: #VU74540
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20129
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input in the web-based management interface. A remote administrator can gain unauthorized access to sensitive information on the system.
Affected software
Cisco Prime Infrastructure
Evolved Programmable Network (EPN) Manager
Evolved Programmable Network (EPN) Manager
How to mitigate CVE-2023-20129
Install update from vendor's website.
Cisco Prime Infrastructure - addressed in versions 3.7.1 update 07, 3.8.1 update 04, 3.9.1 update 03, 3.10.2
Evolved Programmable Network (EPN) Manager - addressed in versions 5.0.2.5, 5.1.4.3, 6.0.2.1, 6.1.1.1
Evolved Programmable Network (EPN) Manager - addressed in versions 5.0.2.5, 5.1.4.3, 6.0.2.1, 6.1.1.1