Junglewise Threat Intelligence

CVE-2025-20272: Cisco Prime Infrastructure and EPNM blind SQL injection in REST APIs

CVE-2025-20272 · Severity: medium · CVSS 4.3 · Published 2025-07-16

Technologies: Cisco Prime Infrastructure, Cisco Evolved Programmable Network Manager. Vendors: Cisco.

Executive brief

Cisco Prime Infrastructure and Evolved Programmable Network Manager are used by IT teams to manage and monitor large-scale enterprise and service provider networks. A security flaw in their programming interface could allow a user with basic login credentials to perform unauthorized database queries. If exploited, an attacker could view sensitive information stored within certain database tables, potentially compromising network configuration details or operational data.

Technical details

A blind SQL injection vulnerability exists in a subset of REST APIs within Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM). The flaw is caused by insufficient validation of user-supplied input in API requests. An authenticated, remote attacker with low privileges can exploit this by sending crafted HTTP requests to the affected API endpoints. A successful exploit allows the attacker to retrieve data from various database tables via blind SQL injection techniques. Cisco has released software updates to address this issue; there are no known workarounds.

Affected products

  • Cisco Prime Infrastructure up to 3.10.6 Security Update 02
  • Cisco Evolved Programmable Network Manager (EPNM) up to 8.0.1, 8.1.1

Timeline

  • 2025-07-16: disclosed
  • 2025-07-16: advisory
  • 2025-07-16: patched

References

Related threats