XSS Vulnerability in Cisco Cyber Vision Center Management Interface
CVE-2025-20357
What is CVE-2025-20357?
A vulnerability exists in the web-based management interface of Cisco Cyber Vision Center, allowing an authenticated remote attacker to perform cross-site scripting (XSS) attacks. This issue arises from inadequate validation of user-supplied input, enabling an attacker to inject malicious code into specific pages of the interface. If successfully exploited, the attacker could execute arbitrary scripts in the context of the affected interface and gain access to sensitive information stored in the user's browser. To exploit this vulnerability, the attacker must possess valid administrative credentials, typically granted by default to all predefined users and any custom users permitted to access the Reports page.
Affected Version(s)
Cisco Cyber Vision 5.1.0
Cisco Cyber Vision 5.1.1
Cisco Cyber Vision 5.1.2