Stored Cross-Site Scripting in Cisco Evolved Programmable Network Manager and Prime Infrastructure
CVE-2025-20280

4.8MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20280?

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure allows authenticated, remote attackers to execute stored cross-site scripting (XSS) attacks. This occurs due to improper validation of user-supplied input, enabling attackers to inject malicious scripts into specific data fields within the interface. If successfully exploited, this could allow arbitrary script code execution in the security context of the affected interface, potentially exposing sensitive browser-based information. Attackers must possess valid administrative credentials to exploit this vulnerability.

Affected Version(s)

Cisco Evolved Programmable Network Manager (EPNM) 8.0.0

Cisco Evolved Programmable Network Manager (EPNM) 8.0.0.1

Cisco Prime Infrastructure 3.0.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20280 : Stored Cross-Site Scripting in Cisco Evolved Programmable Network Manager and Prime Infrastructure