Cyber Resilience

CVE-2023-20258

Cisco Prime Infrastructure ≤ 3.10.4

Published
17 January 2024
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
EPSS Score 0.0069 50th percentile
Risk Priority 50 floored blend · peak EPSS

Summary

CVE-2023-20258 is a medium-severity an unspecified weakness vulnerability in Cisco Prime Infrastructure. Its CVSS base score is 6.5 (Medium).

Operationally, ranked at the 50th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected…

more

application. An attacker could exploit this vulnerability by uploading a document containing malicious serialized Java objects to be processed by the affected application. A successful exploit could allow the attacker to cause the application to execute arbitrary commands.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-20222Same product: Cisco Evolved Programmable Network Manager
CVE-2023-20130Same product: Cisco Evolved Programmable Network Manager
CVE-2023-20257Same product: Cisco Evolved Programmable Network Manager
CVE-2023-20129Same product: Cisco Evolved Programmable Network Manager
CVE-2023-20205Same product: Cisco Evolved Programmable Network Manager
CVE-2025-20280Same product: Cisco Evolved Programmable Network Manager
CVE-2026-20123Same product: Cisco Evolved Programmable Network Manager
CVE-2025-20203Same product: Cisco Evolved Programmable Network Manager
CVE-2025-20272Same product: Cisco Evolved Programmable Network Manager
CVE-2023-20201Same product: Cisco Evolved Programmable Network Manager

Affected Assets

cisco
evolved programmable network manager
≤ 7.1.1
cisco
prime infrastructure
3.10.4 · ≤ 3.10.4

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References