Stored Cross-Site Scripting Vulnerability in Cisco Evolved Programmable Network Manager and Prime Infrastructure
CVE-2025-20203

4.8MEDIUM

Key Information:

Badges

👾 Exploit Exists

Summary

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure enables an authenticated remote attacker to perform a stored cross-site scripting (XSS) attack. This occurs due to inadequate validation of user-supplied input, allowing an attacker with administrative access to embed malicious scripts into specific data fields. When successfully executed, these scripts can run in the context of an affected interface, posing risks such as the unauthorized access to sensitive browser-based information.

Affected Version(s)

Cisco Evolved Programmable Network Manager (EPNM) 1.2.6

Cisco Evolved Programmable Network Manager (EPNM) 1.2.2

Cisco Evolved Programmable Network Manager (EPNM) 1.2.3

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.