Medium severity4.3NVD Advisory· Published Jul 16, 2025· Updated Jun 29, 2026
CVE-2025-20272
CVE-2025-20272
Description
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*range: <8.0.1
- cpe:2.3:a:cisco:evolved_programmable_network_manager:8.1.0:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 3.0.1
cpe:2.3:a:cisco:prime_infrastructure:*:-:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:cisco:prime_infrastructure:*:-:*:*:*:*:*:*range: <3.10.6
- cpe:2.3:a:cisco:prime_infrastructure:3.10.6:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:prime_infrastructure:3.10.6:security_update_01:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 3.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.