Cisco Evolved Programmable Network Manager Arbitrary File Upload Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 4.3 Security Advisory

TL;DR 📌

A medium-severity vulnerability has been identified in the Cisco Evolved Programmable Network Manager (EPNM) that allows authenticated attackers to upload arbitrary files. There are no workarounds available, and affected users should migrate to fixed software releases.

What happened 🕵️‍♂️

A vulnerability in the web-based management interface of Cisco EPNM could allow an authenticated, remote attacker to upload arbitrary files. This issue arises from improper validation of uploaded files, enabling an attacker with valid Config Managers credentials to exploit the vulnerability by sending a crafted file upload request to a specific API endpoint.

Affected products 🖥️

The vulnerability affects Cisco EPNM, specifically:

  • Cisco EPNM Release 8.0 and earlier (requires migration to a fixed release)
  • Cisco EPNM Release 8.1 is not vulnerable.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
8.0 and earlier Migrate to a fixed release.
8.1 Not vulnerable.
1.0 Initial public release.
Cisco EPNM 8.1 8.0 and earlier

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

With a CVSS score of 4.3, this vulnerability is classified as Medium severity. The risk is primarily driven by the requirement for valid authentication, limiting exposure to authenticated users. However, the potential for arbitrary file upload could lead to further exploitation if not addressed.

Fast facts ⚡

  • Vulnerability: Arbitrary file upload in Cisco EPNM
  • CVSS Score: 4.3 (Medium)
  • Exploitation: Requires valid credentials
  • Workarounds: None available
  • Fixed Software: Migrate to a fixed release for versions 8.0 and earlier

For leadership 🧭

Executive summary. An authenticated user with Config Managers credentials on Cisco EPNM can upload arbitrary files through the management interface, with no workaround available other than upgrading. This should be scheduled into a near-term maintenance window rather than treated as an emergency, given the credential requirement.

Why it matters:

  • Exploitation requires only valid Config Managers credentials, not administrative rights, widening the pool of internal accounts that could trigger the file upload
  • The flaw sits in the web-based management interface’s API, a component typically reachable by any operator with console access to EPNM
  • No workaround exists, so exposure persists on Release 8.0 and earlier until the software is migrated to 8.1
  • Arbitrary file upload can be a foothold for further exploitation on the EPNM host, even though this advisory itself does not describe a specific follow-on impact

Now / Next / Later:

  • Now: Identify all EPNM instances still on Release 8.0 or earlier and review which accounts hold Config Managers credentials.
  • Next: Migrate affected EPNM deployments to Release 8.1 in the next scheduled change window, as no interim workaround is offered.
  • Later: Tighten assignment of Config Managers credentials on EPNM to only those who need them, and build EPNM version checks into routine patch-compliance reviews.