CVE-2023-20258
MEDIUMDescription
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected application. An attacker could exploit this vulnerability by uploading a document containing malicious serialized Java objects to be processed by the affected application. A successful exploit could allow the attacker to cause the application to execute arbitrary commands.
Is your site exposed to CVE-2023-20258?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| cisco | evolved_programmable_network_manager |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
| cisco | prime_infrastructure |
References
Frequently Asked Questions
What is CVE-2023-20258? +
How severe is CVE-2023-20258? +
What products are affected by CVE-2023-20258? +
How do I check if I'm vulnerable to CVE-2023-20258? +
Related Vulnerabilities
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after …
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email …
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute …
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload …
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) …
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles …