A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system. To exploit this vulnerability, an attacker must have at least valid Config Managers credentials on the affected device.
History

Tue, 09 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*:*

Fri, 05 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco evolved Programmable Network Manager
Vendors & Products Cisco
Cisco evolved Programmable Network Manager

Wed, 03 Sep 2025 17:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system. To exploit this vulnerability, an attacker must have at least valid Config Managers credentials on the affected device.
Title Cisco Evolved Programmable Network Manager Arbitrary File Upload Vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2025-09-03T17:40:06.650Z

Updated: 2025-09-05T17:07:19.404Z

Reserved: 2024-10-10T19:15:13.251Z

Link: CVE-2025-20287

cve-icon Vulnrichment

Updated: 2025-09-03T17:58:47.691Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-03T18:15:33.373

Modified: 2025-09-09T18:11:59.287

Link: CVE-2025-20287

cve-icon Redhat

No data.