Impact
The vulnerability exploits insufficient validation of user input in the web-based management interface of Cisco Industrial Ethernet 1000 Series Switches. An attacker who authenticates to the system can inject malicious code into specific pages, and a successful exploit allows the attacker to execute arbitrary script code in the context of another logged‑in user.
Affected Systems
Cisco’s Industrial Ethernet Switches product line is affected. The advisory references the IE 1000 Series; specific firmware or model numbers are not listed, but any device running the affected web interface is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. The flaw requires that the attacker have valid user credentials on the affected system; authentication is required to exploit the XSS vulnerability. An attacker can perform the exploit remotely via the switch’s web interface.
OpenCVE Enrichment