PT-2021-2492 · Cisco · Cisco Ios Xe Wireless Controller+1

Published

2021-03-24

·

Updated

2021-03-29

·

CVE-2021-1374

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Cisco IOS XE Wireless Controller software for the Catalyst 9000 Family of switches (affected versions not specified)
Description: A vulnerability in the web-based management interface could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the interface. The issue is due to insufficient validation of user-supplied input. An attacker could exploit this by authenticating as a high-privileged user, adding configurations with malicious code, and persuading another user to click on it. A successful exploit could allow the attacker to execute arbitrary script code or access sensitive browser-based information.
Recommendations: For Cisco IOS XE Wireless Controller software for the Catalyst 9000 Family of switches, update to a version that includes the software updates released by Cisco to address this vulnerability. As a temporary workaround, consider restricting access to the web-based management interface to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01868
CVE-2021-1374

Affected Products

Cisco Ios Xe Wireless Controller
Cisco Ios Xe