Cisco Evolved Programmable Network Manager vulnerabilities
51 known vulnerabilities affecting cisco/evolved_programmable_network_manager.
Total CVEs
51
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH13MEDIUM32LOW1
Vulnerabilities
Page 1 of 3
CVE-2021-44228P1CRITICALCVSS 10.0KEVPoCRansomware≤ 4.1.1v3.0+5 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2019-1821P1CRITICALCVSS 9.8ExploitedPoCfixed in 3.0.12019-05-16
CVE-2019-1821 [CRITICAL] CWE-20 CVE-2019-1821: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied inpu
nvd
CVE-2019-15958P2CRITICALCVSS 9.8fixed in 3.0.22019-11-26
CVE-2019-15958 [CRITICAL] CWE-20 CVE-2019-15958: A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Ne
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input validation during the initial High Availability (HA)
nvd
CVE-2016-1291P2CRITICALCVSS 9.8v1.2.02016-04-06
CVE-2016-1291 [CRITICAL] CWE-20 CVE-2016-1291: Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.
nvd
CVE-2025-20287P2HIGHCVSS 8.8≤ 8.0.02025-09-03
CVE-2025-20287 [HIGH] CWE-434 CVE-2025-20287: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device.
This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit this vulne
nvd
CVE-2016-1289P2CRITICALCVSS 9.8v1.2.02016-07-02
CVE-2016-1289 [CRITICAL] CWE-119 CVE-2016-1289: The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM
The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information via a crafted HTTP request, as demonstrated by discovering managed-device credentials, aka Bug ID CSCuy10231.
nvd
CVE-2021-1487P2HIGHCVSS 8.8fixed in 5.12021-05-22
CVE-2021-1487 [HIGH] CWE-78 CVE-2021-1487: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Prog
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to insufficient validation of user-supplied input to the web-based management interface. An attacker
nvd
CVE-2016-6443P3HIGHCVSS 8.8v1.2v2.02016-10-27
CVE-2016-6443 [HIGH] CWE-89 CVE-2016-6443: A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL datab
A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries that can cause product instability. More Information: CSCva27038, CSCva28335. Known Affected Releases: 3.1(0.128), 1
nvd
CVE-2019-1824P3HIGHCVSS 8.1fixed in 3.0.12019-05-16
CVE-2019-1824 [HIGH] CWE-89 CVE-2019-1824: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this
nvd
CVE-2019-1825P3HIGHCVSS 8.1fixed in 3.0.12019-05-16
CVE-2019-1825 [HIGH] CWE-89 CVE-2019-1825: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this
nvd
CVE-2016-1408P3HIGHCVSS 8.8v1.2.0v1.2.1.3+4 more2016-07-02
CVE-2016-1408 [HIGH] CWE-20 CVE-2016-1408: Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.
nvd
CVE-2026-20155P3HIGHCVSS 8.0fixed in 8.1.22026-04-01
CVE-2026-20155 [HIGH] CWE-862 CVE-2026-20155: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access.
This vulnerability is due to improper authorization checks on a REST API endpoint of an affected device. An
nvd
CVE-2019-1823P3HIGHCVSS 7.2fixed in 3.0.12019-05-16
CVE-2019-1823 [HIGH] CWE-20 CVE-2019-1823: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
nvd
CVE-2019-1822P3HIGHCVSS 7.2fixed in 3.0.12019-05-16
CVE-2019-1822 [HIGH] CWE-20 CVE-2019-1822: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
nvd
CVE-2017-6662P3HIGHCVSS 8.0v1.2.0v1.2.1.3+6 more2017-06-26
CVE-2017-6662 [HIGH] CWE-20 CVE-2017-6662: A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Progr
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code execution. The attacker must have valid user credentials. The vulnerability is du
nvd
CVE-2023-20258P3HIGHCVSS 7.2fixed in 7.1.12024-01-17
CVE-2023-20258 [HIGH] CVE-2023-20258: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an a
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected application. An attacker could exploit this vulnerability by uploading a
nvd
CVE-2016-1406P3HIGHCVSS 8.8v1.2.0v1.2.1.3+2 more2016-05-25
CVE-2016-1406 [HIGH] CWE-284 CVE-2016-1406: The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Networ
The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.
nvd
CVE-2016-1290P3HIGHCVSS 8.1v1.2.02016-04-06
CVE-2016-1290 [HIGH] CWE-264 CVE-2016-1290: The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Networ
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.
nvd
CVE-2019-1819P3MEDIUMCVSS 6.5fixed in 3.0.12019-05-16
CVE-2019-1819 [MEDIUM] CWE-22 CVE-2019-1819: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in HTTP req
nvd
CVE-2019-1820P3MEDIUMCVSS 6.5fixed in 3.0.12019-05-16
CVE-2019-1820 [MEDIUM] CWE-22 CVE-2019-1820: A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolve
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in HTTP req
nvd
1 / 3Next →