Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 4.3 Security Advisory

TL;DR 📌

A medium-severity information disclosure vulnerability has been identified in Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. This flaw allows authenticated, low-privileged users to access sensitive configuration information. Software updates are available to mitigate this risk, but there are no workarounds.

What happened 🕵️‍♂️

A vulnerability exists in the web-based management interface of Cisco EPNM and Cisco Prime Infrastructure. This issue arises from improper validation of requests to API endpoints. An authenticated attacker with low privileges could exploit this vulnerability to view sensitive configuration information that should be restricted.

Affected products 🖥️

  • Cisco Evolved Programmable Network Manager (EPNM) versions 7.1 and earlier, 8.0, and 8.1
  • Cisco Prime Infrastructure versions 3.9 and earlier, 3.10

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
7.1 and earlier Migrate to a fixed release.
8.0 8.0.1
8.1 8.1.2
3.9 and earlier Migrate to a fixed release.
3.10 3.10.6 Security Update 02
1.0 Initial public release.
Cisco EPNM 8.0.1 7.1 and earlier
Cisco EPNM 8.1.2 8.1
Cisco Prime Infrastructure 3.10.6 Security Update 02 3.9 and earlier

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

The highest CVSS score for this vulnerability is 4.3, categorized as Medium. While the risk of exploitation is limited to authenticated users, the potential for unauthorized access to sensitive information remains a concern.

Fast facts ⚡

  • CVE Identifier: CVE-2025-20270
  • Severity: Medium
  • Exploitation: Requires low-privileged user access
  • No known public exploitation or announcements

For leadership 🧭

Executive summary. Any user with a valid, low-privileged login to Cisco EPNM or Prime Infrastructure can view sensitive network configuration data they aren’t authorised to see, because the management API doesn’t check permissions properly. There’s no workaround, so this needs scheduling into a patch window rather than fixing on the fly.

Why it matters:

  • The exposure sits in the web-based management interface’s API endpoints, which validate requests improperly, so privilege checks can be bypassed by any authenticated account.
  • Both EPNM (versions 7.1 and earlier, 8.0, 8.1) and Prime Infrastructure (3.9 and earlier, 3.10) are network management platforms that typically hold device configs, credentials context, and topology data — exactly the kind of information a low-privileged insider or compromised account shouldn’t be able to read.
  • No workaround exists, meaning the only mitigation is upgrading to the fixed release for your specific train.
  • The medium CVSS score reflects that exploitation needs an existing authenticated session, but any account with basic access — not just admins — is sufficient to trigger it.

Now / Next / Later:

  • Now: Identify every EPNM and Prime Infrastructure instance in your estate and check which version and account population (especially low-privileged users) has access to each.
  • Next: Upgrade EPNM to 8.0.1 or 8.1.2 as appropriate, and Prime Infrastructure to 3.10.6 Security Update 02; instances on 7.1-and-earlier or 3.9-and-earlier trains must migrate to a fixed release rather than patch in place.
  • Later: Review who holds low-privileged accounts on these management platforms and tighten access provisioning, since this case shows even minimal access can expose configuration data through the API.