CVE-2025-20272
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Blind SQL Injection Vulnerability
Description
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device.
Weakness: CWE-89
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Evolved Programmable Network Manager | Network & Security Management | cna-assigner |
| Cisco | Cisco Prime Infrastructure | Network & Security Management | cna-assigner |
Vendor-reported products (2)
- Cisco · Cisco Evolved Programmable Network Manager (EPNM)
- Cisco · Cisco Prime Infrastructure
Vendor advisory
Cisco Prime Infrastructure and Evolved Programmable Network Manager Blind SQL Injection Vulnerability
Cisco’s rating: Medium (advisory CVSS 4.3) · Published Jul 16, 2025
Bug IDs: CSCwo76427 , CSCwo97314
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from