Cisco Evolved Programmable Network Manager vulnerabilities
51 known vulnerabilities affecting cisco/evolved_programmable_network_manager.
Total CVEs
51
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH13MEDIUM32LOW1
Vulnerabilities
Page 3 of 3
CVE-2024-20514P4MEDIUMCVSS 5.4fixed in 8.0.02024-11-06
CVE-2024-20514 [MEDIUM] CWE-79 CVE-2024-20514: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability exists because the web-based management interf
nvd
CVE-2025-20272P4MEDIUMCVSS 4.3fixed in 8.0.1v8.1.02025-07-16
CVE-2025-20272 [MEDIUM] CWE-89 CVE-2025-20272: A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmabl
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability b
nvd
CVE-2023-20130P4MEDIUMCVSS 6.5fixed in 5.0.2.5≥ 5.1, < 5.1.4.2+2 more2023-04-05
CVE-2023-20130 [MEDIUM] CWE-27 CVE-2023-20130: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2017-6699P4MEDIUMCVSS 6.1v2.0\(4.0.45b\)v2.0\(4.0.45d\)+1 more2017-07-04
CVE-2017-6699 [MEDIUM] CWE-79 CVE-2017-6699: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc24616 CSCvc35
nvd
CVE-2021-34784P4MEDIUMCVSS 5.4fixed in 5.1.22021-11-04
CVE-2021-34784 [MEDIUM] CWE-79 CVE-2021-34784: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability exists because
nvd
CVE-2023-20131P4MEDIUMCVSS 5.4fixed in 5.0.2.5≥ 5.1, < 5.1.4.2+2 more2023-04-05
CVE-2023-20131 [MEDIUM] CWE-27 CVE-2023-20131: Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cis
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information about these vulnerabilities, see th
nvd
CVE-2026-20075P4MEDIUMCVSS 4.8≤ 7.0≥ 7.1.0, < 7.1.4.1+2 more2026-01-15
CVE-2026-20075 [MEDIUM] CWE-79 CVE-2026-20075: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.
This vulnerability exists because the web-based management i
nvd
CVE-2025-20203P4MEDIUMCVSS 4.8v1.2v1.2.1.2+103 more2025-04-02
CVE-2025-20203 [MEDIUM] CWE-79 CVE-2025-20203: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.
The vulnerability exists because the web-based management int
nvd
CVE-2025-20280P4MEDIUMCVSS 4.8≤ 8.0.0v8.1.02025-09-03
CVE-2025-20280 [MEDIUM] CWE-79 CVE-2025-20280: A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.
This vulnerability exists because the web-based management i
nvd
CVE-2023-20257P4MEDIUMCVSS 4.8fixed in 7.1.12024-01-17
CVE-2023-20257 [MEDIUM] CWE-80 CVE-2023-20257: A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an a
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by submitting malicious i
nvd
CVE-2021-1306P4LOWCVSS 3.4fixed in 5.0.12021-05-22
CVE-2021-1306 [LOW] CWE-73 CVE-2021-1306: A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco I
A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and write arbitrary files to the file system. This vulnerability is due to improper validation of parameters that are sent to
nvd
← Previous3 / 3