Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Sensitive Information Disclosure Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 6.5 Security Advisory

TL;DR 📌

A medium-severity vulnerability has been identified in Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure, allowing authenticated low-privileged attackers to access sensitive files. No workarounds are available, and software updates are necessary to mitigate the risk.

What happened 🕵️‍♂️

A vulnerability exists in the web-based management interface of Cisco EPNM and Cisco Prime Infrastructure due to insufficient input validation for specific HTTP requests. An authenticated, low-privileged remote attacker could exploit this vulnerability to retrieve arbitrary files from the underlying file system of affected devices.

Affected products 🖥️

  • Cisco Evolved Programmable Network Manager (EPNM) versions 7.1 and earlier, 8.0, and 8.1
  • Cisco Prime Infrastructure versions 3.9 and earlier, 3.10

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
7.1 and earlier Migrate to a fixed release.
8.0 Migrate to a fixed release.
8.1 8.1.1
3.9 and earlier Migrate to a fixed release.
3.10 3.10.6 Security Update 02
1.0 Initial public release.
Cisco EPNM 8.1.1 7.1 and earlier, 8.0
Cisco Prime Infrastructure 3.10.6 Security Update 02 3.9 and earlier

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

This vulnerability has a CVSS score of 6.5, indicating a medium risk. While it requires authentication, the ability to access sensitive files poses a significant threat to data confidentiality. Organizations using the affected products should prioritize patching to mitigate potential exploitation.

Fast facts ⚡

  • Vulnerability ID: CVE-2025-20269
  • Severity: Medium (CVSS 6.5)
  • Exploitation: Requires authenticated access
  • Workarounds: None available

For leadership 🧭

Executive summary. Anyone with a valid low-privileged login to Cisco EPNM or Prime Infrastructure can retrieve files from the host filesystem that they should not be able to see, which could expose configuration or credential material. There is no workaround, so patching is the only fix and should be scheduled promptly given these platforms typically hold network-wide credentials and topology data.

Why it matters:

  • The flaw sits in the web-based management interface of EPNM and Prime Infrastructure, tools that centrally manage and hold credentials for large parts of an organisation’s network estate.
  • Exploitation only requires a low-privileged authenticated account, not admin rights, lowering the bar for insider or compromised-account abuse.
  • Insufficient input validation on HTTP requests allows arbitrary file retrieval from the underlying filesystem, risking exposure of sensitive configuration or system files.
  • No workaround exists, so exposure persists on unpatched instances until the fixed release is installed.

Now / Next / Later:

  • Now: Identify every EPNM and Prime Infrastructure instance in your estate and check its version against the affected list (EPNM 7.1 and earlier, 8.0, 8.1; Prime Infrastructure 3.9 and earlier, 3.10).
  • Next: Schedule an upgrade to EPNM 8.1.1 or Prime Infrastructure 3.10.6 Security Update 02 (or migrate off unsupported earlier trains) during the next maintenance window, since no interim workaround is available.
  • Later: Review who holds low-privileged accounts on these management platforms and tighten access controls, since this case shows that even non-admin users can reach sensitive backend files.