Stored Cross-Site Scripting Vulnerability in Cisco EPNM and Prime Infrastructure
CVE-2026-20075

4.8MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-20075?

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure can potentially allow an authenticated remote attacker to execute stored cross-site scripting (XSS) attacks. This arises from the improper validation of user-supplied input in the management interface. By inserting malicious code into specific fields, an attacker with valid administrative credentials could exploit this weakness, resulting in the execution of arbitrary scripts within the affected interface or access to sensitive information stored in the browser. Protection against such vulnerabilities is crucial for maintaining system integrity and safeguarding user data.

Affected Version(s)

Cisco Evolved Programmable Network Manager (EPNM) 3.0.1

Cisco Evolved Programmable Network Manager (EPNM) 3.1.2

Cisco Evolved Programmable Network Manager (EPNM) 1.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.