PT-2025-34116 · Cisco · Cisco Prime Infrastructure+1

Matteo Piciarelli

+1

·

Published

2025-08-20

·

Updated

2025-08-20

·

CVE-2025-20269

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure (affected versions not specified)
Description: A vulnerability exists in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. This issue could allow an authenticated, low-privileged, remote attacker to retrieve arbitrary files from the underlying file system on an affected device. The vulnerability is due to insufficient input validation for specific HTTP requests. An attacker could exploit this issue by sending crafted HTTP requests to the web-based management interface. A successful exploit could allow the attacker to access sensitive files from the affected device.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-10351
CVE-2025-20269

Affected Products

Cisco Evolved Programmable Network Manager
Cisco Prime Infrastructure