VendorsCiscoevolved_programmable_network_managerall versions
Vulnerabilities

Cisco Evolved Programmable Network Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

51CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2019-1821
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Published 2019-05-16 · Modified
10.02 PoCEPSS 0.981
CVE-2016-1289
The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information via a crafted HTTP request, as demonstrated by discovering managed-device credentials, aka Bug ID CSCuy10231.
Published 2016-07-02 · Modified
10.0EPSS 0.062
CVE-2019-15958
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability
Published 2019-11-26 · Modified
10.0EPSS 0.033
CVE-2016-1291
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.
Published 2016-04-06 · Modified
9.8EPSS 0.068
CVE-2019-1822
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Published 2019-05-16 · Modified
9.0EPSS 0.044
CVE-2019-1823
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
Published 2019-05-16 · Modified
9.0EPSS 0.044
CVE-2021-1487
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Command Injection Vulnerability
Published 2021-05-22 · Modified
9.0EPSS 0.021
CVE-2016-6443
A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries that can cause product instability. More Information: CSCva27038, CSCva28335. Known Affected Releases: 3.1(0.128), 1.2(400), 2.0(1.0.34A).
Published 2016-10-27 · Modified
8.8EPSS 0.030
CVE-2016-1408
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.
Published 2016-07-02 · Modified
8.8EPSS 0.025
CVE-2016-1406
The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.
Published 2016-05-25 · Modified
8.8EPSS 0.016
CVE-2025-20287
Cisco Evolved Programmable Network Manager Arbitrary File Upload Vulnerability
Published 2025-09-03 · Analyzed
8.8EPSS 0.003
CVE-2019-1824
Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL Injection Vulnerabilities
Published 2019-05-16 · Modified
8.1EPSS 0.019
CVE-2019-1825
Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL Injection Vulnerabilities
Published 2019-05-16 · Modified
8.1EPSS 0.019
CVE-2016-1290
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.
Published 2016-04-06 · Modified
8.1EPSS 0.015
CVE-2017-6662
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perform remote code execution. The attacker must have valid user credentials. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by convincing the administrator of an affected system to import a crafted XML file with malicious entries which could allow the attacker to read and write files and execute remote code within the application, aka XML Injection. Cisco Prime Infrastructure software releases 1.1 through 3.1.6 are vulnerable. Cisco EPNM software releases 1.2, 2.0, and 2.1 are vulnerable. Cisco Bug IDs: CSCvc23894 CSCvc49561.
Published 2017-06-26 · Modified
8.0EPSS 0.024
CVE-2026-20155
Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability
Published 2026-04-01 · Analyzed
8.0EPSS 0.003
CVE-2023-20258
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected application. An attacker could exploit this vulnerability by uploading a document containing malicious serialized Java objects to be processed by the affected application. A successful exploit could allow the attacker to cause the application to execute arbitrary commands.
Published 2024-01-17 · Modified
7.2EPSS 0.007
CVE-2023-20121
Cisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection Vulnerabilities
Published 2023-04-05 · Modified
6.7EPSS 0.002
CVE-2023-20260
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing of command line arguments to application scripts. An attacker could exploit this vulnerability by issuing a command on the CLI with malicious options. A successful exploit could allow the attacker to gain the escalated privileges of the root user on the underlying operating system.
Published 2024-01-17 · Modified
6.7EPSS 0.002
CVE-2019-1818
Cisco Prime Infrastructure and Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2019-05-16 · Modified
6.5EPSS 0.136
CVE-2019-1820
Cisco Prime Infrastructure and Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2019-05-16 · Modified
6.5EPSS 0.136
CVE-2019-1819
Cisco Prime Infrastructure and Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2019-05-16 · Modified
6.5EPSS 0.136
CVE-2017-3884
A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to access sensitive data. The attacker does not need administrator credentials and could use this information to conduct additional reconnaissance attacks. More Information: CSCvc60031 (Fixed) CSCvc60041 (Fixed) CSCvc60095 (Open) CSCvc60102 (Open). Known Affected Releases: 2.2 2.2(3) 3.0 3.1(0.0) 3.1(0.128) 3.1(4.0) 3.1(5.0) 3.2(0.0) 2.0(4.0.45D).
Published 2017-04-07 · Modified
6.5EPSS 0.021
CVE-2022-20656
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Path Traversal Vulnerability
Published 2024-11-15 · Analyzed
6.5EPSS 0.017
CVE-2021-34707
Cisco Evolved Programmable Network Manager Sensitive Information Disclosure Vulnerability
Published 2021-08-04 · Modified
6.5EPSS 0.011
CVE-2023-20129
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.009
CVE-2023-20131
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.006
CVE-2023-20271
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain and modify sensitive information that is stored in the underlying database.
Published 2024-01-17 · Modified
6.5EPSS 0.005
CVE-2025-20269
Cisco Evolved Programmable Network Manager and Prime Infrastructure Arbitrary File Download Vulnerability
Published 2025-08-20 · Analyzed
6.5EPSS 0.004
CVE-2023-20130
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
Published 2023-04-05 · Modified
6.5EPSS 0.004
CVE-2025-20270
Cisco Evolved Programmable Network Manager Information Disclosure Vulnerability
Published 2025-09-03 · Analyzed
6.5EPSS 0.003
CVE-2017-6699
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc24616 CSCvc35363 CSCvc49574. Known Affected Releases: 3.1(1) 2.0(4.0.45B).
Published 2017-07-04 · Modified
6.1EPSS 0.013
CVE-2022-20659
Cisco Prime Infrastructure and Evolved Programmable Network Manager Cross-Site Scripting Vulnerability
Published 2022-02-17 · Modified
6.1EPSS 0.012
CVE-2022-20657
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Cross-Site Scripting Vulnerability
Published 2024-11-15 · Analyzed
6.1EPSS 0.005
CVE-2023-20222
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published 2023-08-16 · Modified
6.1EPSS 0.005
CVE-2025-20120
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published 2025-04-02 · Analyzed
6.1EPSS 0.003
CVE-2026-20123
Cisco Prime Infrastructure and Evolved Programmable Network Manager Open Redirect Vulnerability
Published 2026-02-04 · Analyzed
6.1EPSS 0.002
CVE-2021-34733
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Information Disclosure Vulnerability
Published 2021-09-02 · Modified
5.5EPSS 0.002
CVE-2021-34784
Cisco Prime Infrastructure and Evolved Programmable Network Manager Stored Cross-Site Scripting Vulnerability
Published 2021-11-04 · Modified
5.4EPSS 0.006
1 / 2Next →