CVE-2025-20272: Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Blind SQL Injection Vulnerability
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20272?
CVE-2025-20272 is classified as a medium severity vulnerability due to its potential for exploitation through SQL injection.
How do I fix CVE-2025-20272?
To mitigate CVE-2025-20272, ensure that you update to the latest patches provided by Cisco for both Prime Infrastructure and Evolved Programmable Network Manager.
Who is affected by CVE-2025-20272?
CVE-2025-20272 affects authenticated, low-privileged users of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager.
What type of attack can be executed with CVE-2025-20272?
CVE-2025-20272 allows attackers to conduct a blind SQL injection attack against vulnerable REST APIs.
Can CVE-2025-20272 be exploited remotely?
Yes, CVE-2025-20272 can be exploited remotely by an authenticated attacker with low privileges.