Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 4.8 Security Advisory

TL;DR 📌

A stored cross-site scripting (XSS) vulnerability has been identified in Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. This vulnerability allows an authenticated attacker to execute arbitrary scripts in the context of the affected interface. Users are advised to upgrade to fixed software versions as there are no workarounds available.

What happened 🕵️‍♂️

A vulnerability in the web-based management interface of Cisco EPNM and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack. This occurs because the interface fails to properly validate user-supplied input. An attacker with valid administrative credentials could exploit this vulnerability by inserting malicious code into specific data fields, potentially executing arbitrary script code or accessing sensitive browser-based information.

Affected products 🖥️

  • Cisco Evolved Programmable Network Manager (EPNM) versions 8.0 and earlier
  • Cisco Prime Infrastructure versions 3.9 and earlier

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
8.0 and earlier Migrate to a fixed release.
8.1 Not vulnerable.
3.9 and earlier Migrate to a fixed release.
3.10 3.10.6 Security Update 02
1.0 Initial public release.
Cisco EPNM Migrate to a fixed release
Cisco Prime Infrastructure 3.10.6 Security Update 02 3.9 and earlier

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

The vulnerability has a CVSS score of 4.8, which is categorized as Medium severity. While it requires valid administrative credentials for exploitation, the potential for executing arbitrary scripts poses a risk to sensitive information within the affected systems.

Fast facts ⚡

  • Vulnerability Type: Stored Cross-Site Scripting (XSS)
  • CVSS Score: 4.8 (Medium)
  • Authentication Required: Yes (valid administrative credentials)
  • Impact: Potential execution of arbitrary scripts and access to sensitive information

For leadership 🧭

Executive summary. A stored cross-site scripting flaw in the management consoles of Cisco EPNM and Cisco Prime Infrastructure lets someone with admin credentials plant script that executes in other users’ browsers when they view the affected page. There is no workaround, so this should be scheduled into the next patch cycle rather than treated as an emergency.

Why it matters:

  • The flaw sits in the web-based management interface used to administer network infrastructure via EPNM or Prime Infrastructure, not a peripheral feature.
  • Malicious script planted in a data field runs in the browser session of whoever next views it, which could include other administrators with broader access.
  • No workaround exists, so the only remediation path is upgrading to a fixed release.
  • Cisco EPNM 8.0 and earlier and Prime Infrastructure 3.9 and earlier are both affected, meaning most currently deployed versions need attention.

Now / Next / Later:

  • Now: Identify which EPNM or Prime Infrastructure instances are running the affected versions (EPNM 8.0 or earlier, Prime Infrastructure 3.9 or earlier) so you know your upgrade scope.
  • Next: Schedule the upgrade: move EPNM to 8.1 or later, and Prime Infrastructure to 3.10.6 Security Update 02 or later, since no interim workaround is available.
  • Later: Review who holds administrative accounts on EPNM and Prime Infrastructure as part of routine access governance, since these interfaces manage network infrastructure and warrant tighter change control.