Sensitive Information Exposure in Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure
CVE-2025-20270
4.3MEDIUM
What is CVE-2025-20270?
A vulnerability exists in the web-based management interface of Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure, allowing an authenticated remote attacker to gain access to sensitive configuration information. This flaw arises from improper validation of requests to API endpoints, enabling a low-privileged user to exploit the system by sending tailored requests. Such unauthorized access to critical information presents a significant risk, necessitating immediate attention to ensure robust security measures are in place.
Affected Version(s)
Cisco Evolved Programmable Network Manager (EPNM) 7.0.0
Cisco Evolved Programmable Network Manager (EPNM) 7.1.1
Cisco Evolved Programmable Network Manager (EPNM) 7.1.2.1