CVE-2025-20272: Cisco Evolved Programmable Network Manager
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device.
Affected products
- Cisco Evolved Programmable Network Manager: before 8.0.1 (fixed in 8.0.1); version 8.1.0 only
- Cisco Prime Infrastructure: before 3.10.6 (fixed in 3.10.6); version 3.10.6 only
Published 2025-07-16. Last modified 2026-06-29.