Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-6662


A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code execution. The attacker must have valid user credentials. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by convincing the administrator of an affected system to import a crafted XML file with malicious entries which could allow the attacker to read and write files and execute remote code within the application, aka XML Injection. Cisco Prime Infrastructure software releases 1.1 through 3.1.6 are vulnerable. Cisco EPNM software releases 1.2, 2.0, and 2.1 are vulnerable. Cisco Bug IDs: CSCvc23894 CSCvc49561.


Published

2017-06-26T07:29:00.170

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.0 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco evolved_programmable_network_manager 1.2.0 Yes
Application cisco evolved_programmable_network_manager 1.2.1.3 Yes
Application cisco evolved_programmable_network_manager 1.2.200 Yes
Application cisco evolved_programmable_network_manager 1.2.300 Yes
Application cisco evolved_programmable_network_manager 1.2.400 Yes
Application cisco evolved_programmable_network_manager 1.2.500 Yes
Application cisco evolved_programmable_network_manager 2.0\(4.0.45d\) Yes
Application cisco evolved_programmable_network_manager 2.0.0 Yes
Application cisco prime_infrastructure 1.2 Yes
Application cisco prime_infrastructure 1.2.0.103 Yes
Application cisco prime_infrastructure 1.2.1 Yes
Application cisco prime_infrastructure 1.3 Yes
Application cisco prime_infrastructure 1.3.0.20 Yes
Application cisco prime_infrastructure 1.4 Yes
Application cisco prime_infrastructure 1.4.0.45 Yes
Application cisco prime_infrastructure 1.4.1 Yes
Application cisco prime_infrastructure 1.4.2 Yes
Application cisco prime_infrastructure 2.0 Yes
Application cisco prime_infrastructure 2.1.0 Yes
Application cisco prime_infrastructure 2.2 Yes
Application cisco prime_infrastructure 2.2\(2\) Yes
Application cisco prime_infrastructure 2.2\(3\) Yes
Application cisco prime_infrastructure 3.0 Yes
Application cisco prime_infrastructure 3.1 Yes
Application cisco prime_infrastructure 3.1\(0.128\) Yes
Application cisco prime_infrastructure 3.1\(4.0\) Yes
Application cisco prime_infrastructure 3.1\(5.0\) Yes
Application cisco prime_infrastructure 3.1.1 Yes
Application cisco prime_infrastructure 3.2\(0.0\) Yes
Application cisco prime_infrastructure 3.2_base Yes

References