Stored Cross-Site Scripting Vulnerability in Cisco Integrated Management Controller
CVE-2025-20342

5.4MEDIUM

What is CVE-2025-20342?

The Cisco Integrated Management Controller (IMC) contains a stored cross-site scripting (XSS) vulnerability in its Virtual Keyboard Video Monitor (vKVM) connection handling. This issue arises from inadequate validation of user-supplied input through the web-based interface, allowing authenticated attackers, who possess valid user credentials and necessary privileges, to inject malicious scripts into the interface. Successful exploitation could enable these attackers to execute arbitrary script code within the affected context or access sensitive browser-related information, posing a significant risk to users interacting with the management console.

Affected Version(s)

Cisco Unified Computing System (Managed) 4.0(1a)

Cisco Unified Computing System (Managed) 3.2(3n)

Cisco Unified Computing System (Managed) 4.1(1a)

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20342 : Stored Cross-Site Scripting Vulnerability in Cisco Integrated Management Controller