PT-2023-4590 · Cisco · Cisco Integrated Management Controller

Mohamed Benkadour

·

Publicado

2023-08-16

·

Atualizado

2024-01-25

·

CVE-2023-20228

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Integrated Management Controller (IMC) (affected versions not specified)
Description The issue exists due to insufficient validation of user input in the web-based management interface. An attacker could exploit this by persuading a user to click a crafted link, potentially allowing the execution of arbitrary script code in the browser of the targeted user or access to sensitive, browser-based information. This could enable a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04997
CVE-2023-20228

Produtos afetados

Cisco Integrated Management Controller