XSS Vulnerability in Cisco Cyber Vision Center Management Interface
CVE-2025-20357

5.4MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
1 October 2025

Badges

👾 Exploit Exists

What is CVE-2025-20357?

A vulnerability exists in the web-based management interface of Cisco Cyber Vision Center, allowing an authenticated remote attacker to perform cross-site scripting (XSS) attacks. This issue arises from inadequate validation of user-supplied input, enabling an attacker to inject malicious code into specific pages of the interface. If successfully exploited, the attacker could execute arbitrary scripts in the context of the affected interface and gain access to sensitive information stored in the user's browser. To exploit this vulnerability, the attacker must possess valid administrative credentials, typically granted by default to all predefined users and any custom users permitted to access the Reports page.

Affected Version(s)

Cisco Cyber Vision 5.1.0

Cisco Cyber Vision 5.1.1

Cisco Cyber Vision 5.1.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20357 : XSS Vulnerability in Cisco Cyber Vision Center Management Interface