CVE-2023-20258
MEDIUMCisco Prime Infrastructure & EPNM Authenticated RCE via Malicious Java Object Upload
Title source: llmDescription
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected application. An attacker could exploit this vulnerability by uploading a document containing malicious serialized Java objects to be processed by the affected application. A successful exploit could allow the attacker to cause the application to execute arbitrary commands.
References (1)
Core 1
Core References
Scores
CVSS v3
6.5
EPSS
0.0005
EPSS Percentile
15.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
Status
published
Products (3)
cisco/evolved_programmable_network_manager
< 7.1.1
cisco/prime_infrastructure
3.10.4 (2 CPE variants)
cisco/prime_infrastructure
< 3.10.4
Published
Jan 17, 2024
Tracked Since
Feb 18, 2026