Prime Infrastructure

Vendor:

First CVE: Mar 7, 2013 · Active for 13 years

89
Total CVEs
More Total CVEs than 99% of tracked products
6.4
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
1.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Prime Infrastructure over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2013
13 years ago
Most Recent CVE
May 6, 2026
82 days ago

CVE Severity & Scoring

Prime Infrastructure89 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local4 (4.5%)
Network75 (84.3%)
Unknown10 (11.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low76 (85.4%)
High3 (3.4%)
Unknown10 (11.2%)
User Interaction
None43 (48.3%)
Unknown10 (11.2%)
Required36 (40.4%)
Privileges Required
Low39 (43.8%)
High12 (13.5%)
None28 (31.5%)
Unknown10 (11.2%)

Top CVEs

Signals from CVEs in this product scope (89 CVEs).

89 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote a
May 16, 20199.894NOYES
A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an
Oct 5, 20189.889NOYES
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable de
May 2, 20189.857NONO
The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive mana
Jul 2, 20169.832NONO
The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC
May 25, 20168.829NONO
Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewing of a log file, aka Bug ID CS
Mar 3, 20168.829NONO
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to
May 22, 20218.828NONO
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remo
May 16, 20196.528NONO
A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system con
Oct 27, 20168.828NONO

Exploit Exposure

Signals from CVEs in this product scope (89 CVEs).

CISA KEV
1 CVE
1.1% of CVEs· 97th percentile
Metasploit
2 CVEs
2.2% of CVEs· 97th percentile
Nuclei
1 CVE
1.1% of CVEs· 96th percentile
ExploitDB
3 CVEs
3.4% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (89 CVEs).

Media Mentions

Signals from CVEs in this product scope (89 CVEs).

Top CNAs Publishing CVEs For Prime Infrastructure

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.9_dp114.80.3%00
3.9.165.70.4%00
3.9.045.70.5%00
3.956.20.6%00
3.8_dp114.80.3%00
3.8.175.50.4%00
3.8.045.70.5%00
3.866.10.7%00
3.7_dp214.80.3%00
3.7_dp114.80.3%00
3.7.125.50.3%00
3.7.045.70.5%00
3.726.10.5%00
3.6_dp114.80.3%00
3.6.045.60.4%00
3.637.51.6%00
3.5_dp414.80.3%00
3.5_dp314.80.3%00
3.5_dp214.80.3%00
3.5_dp114.80.3%00