CVE-2023-20127: Cisco Prime Infrastructure

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see the Details section of this advisory.

Affected products

  • Cisco Prime Infrastructure: up to and including 3.7; from 3.10, before 3.10.2 (fixed in 3.10.2); version 3.8 only; version 3.8.1 only; version 3.9 only; version 3.9.1 only

Published 2023-04-05. Last modified 2026-06-17.