CVE-2022-20656
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Path Traversal Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on the system.
This vulnerability is due to insufficient input validation of the HTTPS URL by the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request that contains directory traversal character sequences to an affected device. A successful exploit could allow the attacker to write arbitrary files to the host system.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-11-02 CVE Reserved
- 2024-11-15 CVE Published
- 2024-11-15 CVE Updated
- 2024-11-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-24: Path Traversal: '../filedir'
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 3.0.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "3.0.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 3.1.2 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "3.1.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 1.2 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "1.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 3.1.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "3.1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 3.1.3 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "3.1.3" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 3.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "3.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 3.0.3 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "3.0.3" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 3.0.2 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "3.0.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 3.0 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "3.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 2.2 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "2.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 1.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 2.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "2.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 2.0 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "2.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 4.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "4.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 4.1.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "4.1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 4.0.3 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "4.0.3" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 4.0.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "4.0.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 4.0.2 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "4.0.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 4.0 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "4.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 5.0 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "5.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 5.0.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "5.0.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 5.1.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "5.1.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 5.1 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "5.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 5.0.2 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "5.0.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Evolved Programmable Network Manager (EPNM) Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" | 5.1.2 Search vendor "Cisco" for product "Cisco Evolved Programmable Network Manager (EPNM)" and version "5.1.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.0.0 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.0.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.1.0 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.1.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.1.5 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.1.5" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 2.1 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "2.1" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 2.0.0 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "2.0.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.6.0 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.6.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.7.0 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.7.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.4.0 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.4.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.3.0 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.3.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.2 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.5.0 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.5.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 2.2 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "2.2" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.9.0 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.9.0" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco Prime Infrastructure Search vendor "Cisco" for product "Cisco Prime Infrastructure" | 3.8.0 Search vendor "Cisco" for product "Cisco Prime Infrastructure" and version "3.8.0" | en |
Affected
|