SQL injection in Evolved Programmable Network (EPN) Manager and Cisco Prime Infrastructure - CVE-2023-20271

 

SQL injection in Evolved Programmable Network (EPN) Manager and Cisco Prime Infrastructure - CVE-2023-20271

Published: January 11, 2024


Vulnerability identifier: #VU85292
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20271
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data in the web-based management interface. A remote user can send a specially crafted request to the affected application and obtain or modify sensitive information that is stored in the underlying database.


Affected software

Evolved Programmable Network (EPN) Manager
Cisco Prime Infrastructure

How to mitigate CVE-2023-20271

Install updates from vendor's website.

Evolved Programmable Network (EPN) Manager - update to 7.1.1
Cisco Prime Infrastructure - update to 3.10.4 Update 2

External References

Related Security Bulletins