CVE-2026-20123

MEDIUM WAF: Medium
CVSS 6.1 Published: 2026-02-04
CWE-601

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page.

WAF Coverage Analysis

Open Redirect Medium WAF Coverage

OWASP: A01:2021 Broken Access Control

941xxx - XSS / XXE

Affected Software

VendorProductVersion
ciscoevolved_programmable_network_managerup to 8.1.1
ciscoprime_infrastructureup to 3.9
ciscoprime_infrastructure3.10 - 3.10.6
ciscoprime_infrastructure3.10.6

References

Back to CVE Database