Impact
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) allows an authenticated, remote attacker to conduct a cross‑site scripting attack against a user of the interface. The flaw results from insufficient validation of user input, enabling the attacker to deceptively persuade a legitimate user to click a crafted link. When the victim’s browser renders the crafted content, the attacker can execute arbitrary script code or exfiltrate sensitive browser‑based information, potentially compromising the victim’s session or leading to further attacks.
Affected Systems
The vulnerability affects Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Standalone), and Cisco Unified Computing System E‑Series Software (UCSE). Version details were not disclosed in the advisory, so any installation of the listed products without an available update is potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker be authenticated to the IMC web interface but only needs to convince an end‑user to interact with a maliciously crafted link. The attack vector is remote, user‑side, relying on social engineering rather than an automated payload.
OpenCVE Enrichment