PT-2025-34116 · Cisco · Cisco Prime Infrastructure+1
Matteo Piciarelli
+1
·
Published
2025-08-20
·
Updated
2025-08-20
·
CVE-2025-20269
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure (affected versions not specified)
Description:
A vulnerability exists in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. This issue could allow an authenticated, low-privileged, remote attacker to retrieve arbitrary files from the underlying file system on an affected device. The vulnerability is due to insufficient input validation for specific HTTP requests. An attacker could exploit this issue by sending crafted HTTP requests to the web-based management interface. A successful exploit could allow the attacker to access sensitive files from the affected device.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Evolved Programmable Network Manager
Cisco Prime Infrastructure