PT-2025-35808 · Cisco · Cisco Evolved Programmable Network Manager

Matteo Piciarelli

+1

·

Published

2025-09-03

·

Updated

2025-09-09

·

CVE-2025-20287

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Evolved Programmable Network Manager (EPNM) (affected versions not specified)
Description A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) may allow an authenticated, remote attacker to upload arbitrary files to an affected device. This issue is due to improper validation of files uploaded to the web-based management interface. An attacker could exploit this by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system. An attacker must have valid Config Managers credentials on the affected device to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-12713
CVE-2025-20287

Affected Products

Cisco Evolved Programmable Network Manager