Reflected XSS Vulnerability in Cisco IMC Management Interface
CVE-2026-20085

6.1MEDIUM

What is CVE-2026-20085?

A vulnerability present in the web-based management interface of Cisco IMC allows for reflected Cross-Site Scripting (XSS) attacks. This issue arises from inadequate validation of user input, enabling attackers to potentially trick users into clicking on malicious links. If successfully exploited, this vulnerability can allow an attacker to run arbitrary script code within the user's browser environment, leading to unauthorized access to sensitive browser-stored information.

Affected Version(s)

Cisco Enterprise NFV Infrastructure Software 4.1.1

Cisco Enterprise NFV Infrastructure Software 3.9.1

Cisco Enterprise NFV Infrastructure Software 3.5.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.