CVE-2025-20270
published 2025-09-03CVE-2025-20270: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an…
PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.29%
20.6th percentile
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system.
This vulnerability is due to improper validation of requests to API endpoints. An attacker could exploit this vulnerability by sending a valid request to a specific API endpoint within the affected system. A successful exploit could allow a low-privileged user to view sensitive configuration information on the affected system that should be restricted. To exploit this vulnerability, an attacker must have access as a low-privileged user.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_evolved_programmable_network_manager | — | — |
| cisco | cisco_evolved_programmable_network_manager | — | — |
| cisco | cisco_evolved_programmable_network_manager | — | — |
| cisco | cisco_evolved_programmable_network_manager | — | — |
| cisco | cisco_evolved_programmable_network_manager | — | — |
| cisco | cisco_evolved_programmable_network_manager | — | — |
| cisco | cisco_evolved_programmable_network_manager | — | — |
| cisco | cisco_evolved_programmable_network_manager | — | — |
| cisco | cisco_evolved_programmable_network_manager | — | — |
| cisco | cisco_evolved_programmable_network_manager | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
| cisco | cisco_prime_infrastructure | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_msrc7.5HIGH
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rxmg-x4qr-j69v: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow
ghsa_unreviewed·2025-09-09
CVE-2025-20270 [MEDIUM] CWE-200 GHSA-rxmg-x4qr-j69v: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system.
This vulnerability is due to improper validation of requests to API endpoints. An attacker could exploit this vulnerability by sending a valid request to a specific API endpoint within the affected system. A successful exploit could allow a low-privileged user to view sensitive configuration information on the affected system that should be restricted. To exploit this vulnerability, an attacker must have access as a low-privileged user.
Cisco
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability
vendor_cisco·2025-09-03·CVSS 4.3
CVE-2025-20270 [MEDIUM] CWE-200 Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system.
This vulnerability is due to improper validation of requests to API endpoints. An attacker could exploit this vulnerability by sending a valid request to a specific API endpoint within the affected system. A successful exploit could allow a low-privileged user to view sensitive configuration information on the affected system that should be restricted. To exploit this vulnerability, an attacker must have access as a low-privileged user.
Cisc
Microsoft
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file as demonstrated by input that only c
vendor_msrc·2021-03-09·CVSS 7.5
CVE-2021-20270 [HIGH] CWE-835 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file as demonstrated by input that only c
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file as demonstrated by input that only contains the "exception" keyword.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products i
Cisco
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20270 Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability
CVE-2025-20270: Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system. This vulnerability is due to improper validation of requests to API endpoints. An attacker could exploit this vulnerability by sending a valid request to a specific API endpoint within the affected system. A successful exploit could allow a low-privileged user to view sensitive configuration information on the affected system that should be restricted. To exploit this vulnerability, an attacker must have access as a low-privileg
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-03
Published