CVE-2025-20272 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-p…
Medium CVSS: 4.3

CVE-2025-20272

A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device.
Vendor
Cisco
Product
Prime Infrastructure
CWE
CWE-89
Yayın Tarihi
2025-07-16 17:15:28
Güncelleme
2025-07-31 15:15:35
Source Identifier
psirt@cisco.com
KEV Date Added
-

Kategoriler

Referanslar