HomeCiscoCVE-2026-20123

CVE-2026-20123

MEDIUM
4.3CVSS
Published: 2026-02-04
Updated: 2026-03-10
AI Analysis

Description

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
none
Integrity
low
Availability
none
Weaknesses
CWE-601

Metadata

Primary Vendor
CISCO
Published
2/4/2026
Last Modified
3/10/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

cisco : evolved_programmable_network_managercisco : prime_infrastructurecisco : prime_infrastructurecisco : prime_infrastructure

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2026-20123 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com