Description
A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.

This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of another user. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.
Published: 2026-08-19
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exploits insufficient validation of user input in the web-based management interface of Cisco Industrial Ethernet 1000 Series Switches. An attacker who authenticates to the system can inject malicious code into specific pages, and a successful exploit allows the attacker to execute arbitrary script code in the context of another logged‑in user.

Affected Systems

Cisco’s Industrial Ethernet Switches product line is affected. The advisory references the IE 1000 Series; specific firmware or model numbers are not listed, but any device running the affected web interface is vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. The flaw requires that the attacker have valid user credentials on the affected system; authentication is required to exploit the XSS vulnerability. An attacker can perform the exploit remotely via the switch’s web interface.

Generated by OpenCVE AI on August 20, 2026 at 14:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy any Cisco firmware or patch that fixes the XSS validation flaw as soon as it becomes available.
  • Limit management interface access to trusted IP ranges or VPN endpoints so that only authorized personnel can reach the switch.
  • Require multi‑factor authentication for all accounts that can access the switch’s web interface to reduce the risk of credential compromise.

Generated by OpenCVE AI on August 20, 2026 at 14:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco cisco Industrial Ethernet Switches
Vendors & Products Cisco
Cisco cisco Industrial Ethernet Switches

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of another user. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.
Title Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Cisco Cisco Industrial Ethernet Switches
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-19T19:19:39.460Z

Reserved: 2025-10-08T11:59:15.399Z

Link: CVE-2026-20232

cve-icon Vulnrichment

Updated: 2026-08-19T19:19:31.484Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T17:18:39.390

Modified: 2026-08-20T13:01:19.947

Link: CVE-2026-20232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T14:45:16Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)