Stored Cross-Site Scripting in Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure
CVE-2025-20120

6.1MEDIUM

Key Information:

Badges

👾 Exploit Exists

Summary

A vulnerability exists in the web-based management interface of Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure, where insufficient validation of user-supplied input allows for stored cross-site scripting (XSS) attacks. This flaw enables an unauthenticated, remote attacker to inject malicious scripts into specific pages of the interface. If successfully executed, this could allow the attacker to run arbitrary script code within the context of the affected interface, potentially exposing sensitive browser-based information to unauthorized access. Users and organizations utilizing these systems are advised to implement security measures to mitigate this risk.

Affected Version(s)

Cisco Evolved Programmable Network Manager (EPNM) 1.2.6

Cisco Evolved Programmable Network Manager (EPNM) 1.2.2

Cisco Evolved Programmable Network Manager (EPNM) 1.2.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.