PT-2025-14531 · Cisco · Cisco Prime Infrastructure+1

Roberto Petrillo

·

Published

2025-04-02

·

Updated

2025-08-01

·

CVE-2025-20203

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure (affected versions not specified)
Description A stored cross-site scripting (XSS) attack is possible due to the web-based management interface not properly validating user-supplied input. An attacker with valid administrative credentials could insert malicious code into specific data fields, allowing them to execute arbitrary script code or access sensitive browser-based information.
Recommendations For Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure, as a temporary workaround, consider restricting access to the web-based management interface until a patch is available. Avoid using the interface with administrative credentials until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-03881
CVE-2025-20203

Affected Products

Cisco Epnm
Cisco Prime Infrastructure