Stored Cross-Site Scripting Flaw in Cisco Industrial Ethernet Switches
CVE-2026-20232

5.4MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
19 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-20232?

A vulnerability exists in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches, stemming from inadequate validation of user inputs. This flaw enables authenticated remote attackers to perform stored cross-site scripting (XSS) attacks. By injecting malicious scripts into specific pages within the interface, attackers can execute arbitrary script code in the context of another user's session. To successfully exploit this vulnerability, the assailant must possess valid user credentials for the affected system.

Affected Version(s)

Cisco Industrial Ethernet Switches 1.1

Cisco Industrial Ethernet Switches 1.2

Cisco Industrial Ethernet Switches 1.8.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.