Cross-Site Scripting Vulnerability in Cisco Catalyst Center Web Management Interface
CVE-2025-20353
6.1MEDIUM
What is CVE-2025-20353?
A security flaw in the web-based management interface of Cisco Catalyst Center allows unauthenticated remote attackers to perform cross-site scripting attacks. This issue arises from insufficient validation of user input. By tricking users into clicking a malicious link, attackers can execute arbitrary scripts in the context of the management interface, potentially accessing sensitive browser information and compromising the security of the affected device. It is crucial for users to be aware of this vulnerability and to take necessary precautions.
Affected Version(s)
Cisco Digital Network Architecture Center (DNA Center) 2.1.1.0
Cisco Digital Network Architecture Center (DNA Center) 2.1.1.3
Cisco Digital Network Architecture Center (DNA Center) 2.1.2.0