Vulnerabilities > Cisco > Prime Infrastructure > 3.2.0.0

DATE CVE VULNERABILITY TITLE RISK
2019-05-16 CVE-2019-1818 Path Traversal vulnerability in Cisco Prime Infrastructure
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted.
network
low complexity
cisco CWE-22
6.5
2019-02-21 CVE-2019-1659 Improper Certificate Validation vulnerability in Cisco Prime Infrastructure
A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack against the Secure Sockets Layer (SSL) tunnel established between ISE and PI.
network
high complexity
cisco CWE-295
7.4
2018-10-05 CVE-2018-15379 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Prime Infrastructure
A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file.
network
low complexity
cisco CWE-732
critical
9.8
2018-01-18 CVE-2018-0096 Incorrect Authorization vulnerability in Cisco Prime Infrastructure 3.2(0.0)/3.3(0.0)
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to perform a privilege escalation in which one virtual domain user can view and modify another virtual domain configuration.
network
high complexity
cisco CWE-863
5.9
2017-08-17 CVE-2017-6782 Code Injection vulnerability in Cisco Prime Infrastructure 3.2(0.0)
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application.
network
low complexity
cisco CWE-94
5.4
2017-06-26 CVE-2017-6662 XXE vulnerability in Cisco products
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code execution.
network
low complexity
cisco CWE-611
8.0
2017-04-07 CVE-2017-3884 Information Exposure vulnerability in Cisco products
A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to access sensitive data.
network
low complexity
cisco CWE-200
6.5