CVE-2025-20272
EUVD-2025-2171316.07.2025, 17:15
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cisco | prime_infrastructure | 𝑥 < 3.10.6 |
| cisco | prime_infrastructure | 3.10.6 |
| cisco | prime_infrastructure | 3.10.6:security_update_01 |
| cisco | evolved_programmable_network_manager | 𝑥 < 8.0.1 |
| cisco | evolved_programmable_network_manager | 8.1.0 |
𝑥
= Vulnerable software versions