Impact
A stored cross‑site scripting flaw exists in the web‑based management interface of Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure because user input is not properly validated. The vulnerability allows an authenticated attacker to inject malicious script code into specific data fields, which then executes when other users view that data. Successful exploitation can lead to arbitrary script execution in the web interface context or theft of browser‑based information such as session tokens.
Affected Systems
The flaw affects Cisco Evolved Programmable Network Manager, including version 8.0.0 and earlier releases, and Cisco Prime Infrastructure. All installations that expose the web‑based interface and allow administrative authentication are susceptible, regardless of network location.
Risk and Exploitability
The vulnerability has a CVSS score of 4.8, indicating moderate severity, and an EPSS score of less than 1%, indicating low exploit probability. It is not listed in the CISA KEV catalog. Attack requires valid administrative credentials and occurs via the web interface, so mitigation focuses on patching, credential hardening and access control. Because the code runs in the victim's browser, an attacker could hijack sessions or perform other malicious actions against users accessing the interface.
OpenCVE Enrichment