Rewterz
Rewterz Threat Alert – CoinMiner Malware – Active IOCs
January 11, 2024
Rewterz
Rewterz Threat Advisory – Multiple Intel NUC BIOS Vulnerabilities
January 11, 2024

Rewterz Threat Advisory – Multiple Cisco EPNM and Prime Infrastructure Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2023-20257 CVSS:4.8

Cisco EPNM and Prime Infrastructure are vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the web-based management interface. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2023-20260 CVSS:6

Cisco EPNM and Prime Infrastructure could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper processing of command line arguments to application scripts. By sending specially a crafted command on the CLI, an authenticated attacker could exploit this vulnerability to gain elevated privileges to root user on the underlying operating system.

CVE-2023-20271 CVSS:6.5

Cisco EPNM and Cisco Prime Infrastructure are vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

Impact

  • Cross-Site Scripting
  • Privilege Escalation
  • Data Manipulation

Indicators Of Compromise

CVE

  • CVE-2023-20257
  • CVE-2023-20260
  • CVE-2023-20271

Affected Vendors

Cisco

Affected Products

  • Cisco Prime Infrastructure
  • Cisco Evolved Programmable Network Manager

Remediation

Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.

Cisco Security Advisory