CVE-2025-20272

EUVD-2025-21713
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
ciscoprime_infrastructure
𝑥
< 3.10.6
ciscoprime_infrastructure
3.10.6
ciscoprime_infrastructure
3.10.6:security_update_01
ciscoevolved_programmable_network_manager
𝑥
< 8.0.1
ciscoevolved_programmable_network_manager
8.1.0
𝑥
= Vulnerable software versions