Cisco Prime Infrastructure & EPNM XSS in Web Interface
CVE-2023-20222 Published on August 16, 2023
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Vulnerability Analysis
CVE-2023-20222 is exploitable with network access, requires user interaction and user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a Basic XSS Vulnerability?
The software receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages. This may allow such characters to be treated as control characters, which are executed client-side in the context of the user's session. Although this can be classified as an injection problem, the more pertinent issue is the improper conversion of such special characters to respective context-appropriate entities before displaying them to the user.
CVE-2023-20222 has been classified to as a Basic XSS vulnerability or weakness.
Products Associated with CVE-2023-20222
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2023-20222 are published in these products:
Affected Versions
Cisco Prime Infrastructure:- Version 2.0.0 is affected.
- Version 2.0.10 is affected.
- Version 2.0.39 is affected.
- Version 2.1.0 is affected.
- Version 2.1.1 is affected.
- Version 2.1.2 is affected.
- Version 2.1.56 is affected.
- Version 2.2.0 is affected.
- Version 2.2.1 is affected.
- Version 2.2.2 is affected.
- Version 2.2.3 is affected.
- Version 2.2.10 is affected.
- Version 2.2.8 is affected.
- Version 2.2.4 is affected.
- Version 2.2.7 is affected.
- Version 2.2.5 is affected.
- Version 2.2.9 is affected.
- Version 2.2.1 Update 01 is affected.
- Version 2.2.2 Update 03 is affected.
- Version 2.2.2 Update 04 is affected.
- Version 2.2.3 Update 02 is affected.
- Version 2.2.3 Update 03 is affected.
- Version 2.2.3 Update 04 is affected.
- Version 2.2.3 Update 05 is affected.
- Version 2.2.3 Update 06 is affected.
- Version 3.0.0 is affected.
- Version 3.0.1 is affected.
- Version 3.0.2 is affected.
- Version 3.0.3 is affected.
- Version 3.0.4 is affected.
- Version 3.0.6 is affected.
- Version 3.0.5 is affected.
- Version 3.0.7 is affected.
- Version 3.1.0 is affected.
- Version 3.1.1 is affected.
- Version 3.1.7 is affected.
- Version 3.1.5 is affected.
- Version 3.1.2 is affected.
- Version 3.1.3 is affected.
- Version 3.1.4 is affected.
- Version 3.1.6 is affected.
- Version 3.2.2 is affected.
- Version 3.2.0-FIPS is affected.
- Version 3.2.1 is affected.
- Version 3.3.0 is affected.
- Version 3.3.1 is affected.
- Version 3.3.0 Update 01 is affected.
- Version 3.4.0 is affected.
- Version 3.4.1 is affected.
- Version 3.4.2 is affected.
- Version 3.4.1 Update 01 is affected.
- Version 3.4.1 Update 02 is affected.
- Version 3.4.2 Update 01 is affected.
- Version 3.5.0 is affected.
- Version 3.5.1 is affected.
- Version 3.5.0 Update 01 is affected.
- Version 3.5.0 Update 02 is affected.
- Version 3.5.0 Update 03 is affected.
- Version 3.5.1 Update 01 is affected.
- Version 3.5.1 Update 02 is affected.
- Version 3.5.1 Update 03 is affected.
- Version 3.6.0 is affected.
- Version 3.6.0 Update 01 is affected.
- Version 3.6.0 Update 02 is affected.
- Version 3.6.0 Update 03 is affected.
- Version 3.6.0 Update 04 is affected.
- Version 2.1 is affected.
- Version 2.2 is affected.
- Version 3.2 is affected.
- Version 3.4_DP1 is affected.
- Version 3.4_DP3 is affected.
- Version 3.4_DP2 is affected.
- Version 3.5_DP1 is affected.
- Version 3.4_DP7 is affected.
- Version 3.4_DP10 is affected.
- Version 3.4_DP5 is affected.
- Version 3.1_DP15 is affected.
- Version 3.4_DP11 is affected.
- Version 3.4_DP8 is affected.
- Version 3.7_DP1 is affected.
- Version 3.3_DP4 is affected.
- Version 3.10_DP1 is affected.
- Version 3.8_DP1 is affected.
- Version 3.7_DP2 is affected.
- Version 3.6_DP1 is affected.
- Version 3.1_DP16 is affected.
- Version 3.5_DP4 is affected.
- Version 3.3_DP3 is affected.
- Version 3.2_DP2 is affected.
- Version 3.4_DP4 is affected.
- Version 3.1_DP14 is affected.
- Version 3.1_DP6 is affected.
- Version 3.1_DP9 is affected.
- Version 3.4_DP6 is affected.
- Version 3.2_DP3 is affected.
- Version 3.4_DP9 is affected.
- Version 3.3_DP2 is affected.
- Version 3.2_DP1 is affected.
- Version 3.1_DP10 is affected.
- Version 3.9_DP1 is affected.
- Version 3.3_DP1 is affected.
- Version 3.1_DP13 is affected.
- Version 3.5_DP2 is affected.
- Version 3.1_DP12 is affected.
- Version 3.1_DP4 is affected.
- Version 3.5_DP3 is affected.
- Version 3.1_DP8 is affected.
- Version 3.1_DP7 is affected.
- Version 3.2_DP4 is affected.
- Version 3.1_DP11 is affected.
- Version 3.1_DP5 is affected.
- Version 3.7.0 is affected.
- Version 3.7.1 is affected.
- Version 3.7.1 Update 04 is affected.
- Version 3.7.1 Update 06 is affected.
- Version 3.7.1 Update 07 is affected.
- Version 3.7.1 Update 03 is affected.
- Version 3.7.0 Update 03 is affected.
- Version 3.7.1 Update 01 is affected.
- Version 3.7.1 Update 02 is affected.
- Version 3.7.1 Update 05 is affected.
- Version 3.8.0 is affected.
- Version 3.8.1 is affected.
- Version 3.8.1 Update 02 is affected.
- Version 3.8.1 Update 04 is affected.
- Version 3.8.1 Update 01 is affected.
- Version 3.8.1 Update 03 is affected.
- Version 3.8.0 Update 01 is affected.
- Version 3.8.0 Update 02 is affected.
- Version 3.9.0 is affected.
- Version 3.9.1 is affected.
- Version 3.9.1 Update 02 is affected.
- Version 3.9.1 Update 03 is affected.
- Version 3.9.1 Update 01 is affected.
- Version 3.9.1 Update 04 is affected.
- Version 3.9.0 Update 01 is affected.
- Version 3.10.0 is affected.
- Version 3.10.3 is affected.
- Version 3.10.1 is affected.
- Version 3.10.2 is affected.
- Version 3.10.4 is affected.
- Version N/A is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.