Cross-Site Scripting Vulnerability in Cisco Integrated Management Controller Interface
CVE-2023-20228

6.1MEDIUM

Summary

A vulnerability has been identified in the web-based management interface of Cisco Integrated Management Controller (IMC). This issue stems from inadequate validation of user input, which could enable an unauthorized remote attacker to execute cross-site scripting (XSS) attacks against users interacting with the interface. By enticing a user to click on a specially crafted link, the attacker may run arbitrary script code within the user's browser or access sensitive data managed through the browser. This highlights the importance of input validation and safe browsing practices.

Affected Version(s)

Cisco Identity Services Engine Software

Cisco Unified Computing System (Standalone) 3.1(1d)

Cisco Unified Computing System (Standalone) 3.1(2b)

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.