📦 Evolved Programmable Network Manager

by Cisco

🔍 What is Evolved Programmable Network Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-44228

CRITICAL CVSS 10.0 Dec 10, 2021

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by exploiting JNDI lookups in log messages. This affects a...

CVE-2021-1487

HIGH CVSS 8.8 May 22, 2021

This vulnerability allows authenticated remote attackers to execute arbitrary commands on Cisco Prime Infrastructure and EPN Manager systems via crafted HTTP requests to the web management interface. ...

CVE-2026-20075

MEDIUM CVSS 4.8 Jan 15, 2026

This stored XSS vulnerability in Cisco EPNM and Prime Infrastructure allows authenticated administrators to inject malicious scripts into the web interface. When other users view the compromised inter...

CVE-2025-20280

MEDIUM CVSS 4.8 Sep 3, 2025

An authenticated attacker with administrative credentials can inject malicious scripts into Cisco EPNM/Prime Infrastructure web interface fields, which then execute in victims' browsers when they view...

CVE-2025-20287

MEDIUM CVSS 4.3 Sep 3, 2025

This vulnerability allows authenticated attackers with Config Managers credentials to upload arbitrary files to Cisco EPNM systems via the web management interface. It affects Cisco Evolved Programmab...

CVE-2025-20272

MEDIUM CVSS 4.3 Jul 16, 2025

An authenticated low-privileged attacker can exploit insufficient input validation in certain REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager to conduct blind SQ...

CVE-2025-20120

MEDIUM CVSS 6.1 Apr 2, 2025

An unauthenticated remote attacker can inject malicious scripts into Cisco EPNM and Prime Infrastructure web interfaces, which then execute in victims' browsers when they view compromised pages. This ...

CVE-2022-20657

MEDIUM CVSS 6.1 Nov 15, 2024

This is a cross-site scripting (XSS) vulnerability in Cisco PI and EPNM web management interfaces that allows unauthenticated attackers to execute malicious scripts in users' browsers. Attackers can s...