CVE-2023-20131: Cisco Evolved Programmable Network Manager

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see the Details section of this advisory.

Affected products

  • Cisco Evolved Programmable Network Manager: before 5.0.2.5 (fixed in 5.0.2.5); from 5.1, before 5.1.4.2 (fixed in 5.1.4.2); from 6.0, before 6.0.2.1 (fixed in 6.0.2.1); from 6.1, before 6.1.1.1 (fixed in 6.1.1.1)
  • Cisco Prime Infrastructure: up to and including 3.7; from 3.10, before 3.10.2 (fixed in 3.10.2); version 3.8 only; version 3.8.1 only; version 3.9 only; version 3.9.1 only

Published 2023-04-05. Last modified 2026-06-17.