Cisco Evolved Programmable Network Manager
cpe:2.3:a:cisco:evolved_programmable_network_manager:*:*:*:*:*:*:*
A vulnerability exists in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM), allowing authenticated, remote attackers to upload arbitrary files to affected devices. This issue arises from improper validation of uploaded files. Exploitation involves sending a crafted file upload request to a specific API endpoint. Successful exploitation requires valid Config Managers credentials on the affected device.
Exploitation of this vulnerability could lead to unauthorized file uploads on the affected system.
Cisco EPNM releases 8.0 and earlier are vulnerable. Users should upgrade to a fixed release. For guidance on upgrading, consult the Cisco Security Vulnerability Policy or contact the Cisco Technical Assistance Center (TAC).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.