Cisco Prime Infrastructure and Evolved Programmable Network Manager Blind SQL Injection Vulnerability

Vulnerability

A blind SQL injection vulnerability has been identified in a subset of REST APIs within Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM). This vulnerability allows authenticated, low-privileged, remote attackers to conduct SQL injection attacks, exploiting insufficient validation of user-supplied input. By sending crafted requests to affected APIs, attackers could potentially access data from certain database tables on the impacted device.

Impact

Exploitation of this vulnerability could allow an attacker to view data in some database tables on the affected device.

Remediation

Cisco has released software updates to address this vulnerability. For Cisco EPNM, users should upgrade to version 8.0.1 or 8.1.1. For Cisco Prime Infrastructure, the recommended version is 3.10.6 Security Update 02.

Added: Jul 16, 2025, 5:48 PM
Updated: Jul 16, 2025, 5:48 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
4.9
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.