VYPR
Medium severity4.3NVD Advisory· Published Jul 16, 2025· Updated Jun 29, 2026

CVE-2025-20272

CVE-2025-20272

Description

A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*range: <8.0.1
    • cpe:2.3:a:cisco:evolved_programmable_network_manager:8.1.0:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 3.0.1
  • cpe:2.3:a:cisco:prime_infrastructure:*:-:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:cisco:prime_infrastructure:*:-:*:*:*:*:*:*range: <3.10.6
    • cpe:2.3:a:cisco:prime_infrastructure:3.10.6:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:prime_infrastructure:3.10.6:security_update_01:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 3.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.