Sensitive Information Exposure in Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure
CVE-2025-20270

4.3MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20270?

A vulnerability exists in the web-based management interface of Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure, allowing an authenticated remote attacker to gain access to sensitive configuration information. This flaw arises from improper validation of requests to API endpoints, enabling a low-privileged user to exploit the system by sending tailored requests. Such unauthorized access to critical information presents a significant risk, necessitating immediate attention to ensure robust security measures are in place.

Affected Version(s)

Cisco Evolved Programmable Network Manager (EPNM) 7.0.0

Cisco Evolved Programmable Network Manager (EPNM) 7.1.1

Cisco Evolved Programmable Network Manager (EPNM) 7.1.2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20270 : Sensitive Information Exposure in Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure