Stored Cross-Site Scripting Flaw in Cisco Industrial Ethernet Switches
CVE-2026-20232
5.4MEDIUM
What is CVE-2026-20232?
A vulnerability exists in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches, stemming from inadequate validation of user inputs. This flaw enables authenticated remote attackers to perform stored cross-site scripting (XSS) attacks. By injecting malicious scripts into specific pages within the interface, attackers can execute arbitrary script code in the context of another user's session. To successfully exploit this vulnerability, the assailant must possess valid user credentials for the affected system.
Affected Version(s)
Cisco Industrial Ethernet Switches 1.1
Cisco Industrial Ethernet Switches 1.2
Cisco Industrial Ethernet Switches 1.8.0