A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper input validation in the web UI. An authenticated attacker could exploit this vulnerability by injecting malicious code into specific pages of the web UI. A successful exploit could allow the attacker to execute arbitrary script code in the context of the web UI or access sensitive, browser-based information.
Conclusion & alert: CVE-2025-20116 is rated Low Risk (26.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-20 | 0.04% | 0.06% | +0.02% |
| 2 | 2026-04-08 | 0.05% | 0.04% | -0.01% |
| 3 | 2025-11-12 | — | 0.05% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.8 | 3.1 | MEDIUM |
|
1.7 | 2.7 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cisco | application_policy_infrastructure_controller | 3.2\(1l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(1l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(1m\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(1m\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(2l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(2l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(2o\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(2o\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(3i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(3i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(3j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(3j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(3n\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(3n\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(3o\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(3o\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(3r\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(3r\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(3s\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(3s\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(4d\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(4d\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(4e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(4e\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(5d\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(5d\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(5e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(5e\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(5f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(5f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(6i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(6i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(7f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(7f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(7k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(7k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(8d\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(8d\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(9b\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(9b\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(9f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(9f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(9h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(9h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(10e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(10e\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(10f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(10f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(10g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(10g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 3.2\(41d\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.2\(41d\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.0\(1h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.0\(1h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.0\(2c\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.0\(2c\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.0\(3c\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.0\(3c\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.0\(3d\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.0\(3d\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(1a\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(1a\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(1i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(1i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(1j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(1j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(1k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(1k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(1l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(1l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(2g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(2g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(2m\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(2m\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(2o\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(2o\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(2s\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(2s\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(2u\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(2u\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(2w\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(2w\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.1\(2x\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.1\(2x\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(1g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(1g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(1i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(1i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(1j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(1j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(1l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(1l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(2e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(2e\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(2f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(2f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(2g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(2g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(3j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(3j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(3l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(3l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(3n\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(3n\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(3q\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(3q\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(4i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(4i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(4k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(4k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(4o\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(4o\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(4p\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(4p\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(5k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(5k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(5l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(5l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(5n\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(5n\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(6d\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(6d\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(6g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(6g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(6h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(6h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(6l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(6l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(6o\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(6o\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(7f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(7f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(7l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(7l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(7q\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(7q\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(7r\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(7r\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(7s\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(7s\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(7t\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(7t\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(7u\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(7u\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(7v\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(7v\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 4.2\(7w\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:4.2\(7w\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 5.0\(1k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:5.0\(1k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 5.0\(1l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:5.0\(1l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 5.0\(2e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:5.0\(2e\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 5.0\(2h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:5.0\(2h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 5.1\(1h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:5.1\(1h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 5.1\(2e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:5.1\(2e\):*:*:*:*:*:*:* |