PT-2022-3759 · Cisco · Cisco Ucs Director

Published

2022-05-18

·

Updated

2022-06-09

·

CVE-2022-20765

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco UCS Director (affected versions not specified)
Description The issue is related to insufficient neutralization of special characters in the web interface of Cisco UCS Director, allowing for cross-site scripting attacks. An attacker could exploit this by submitting custom JavaScript to affected web applications, potentially rewriting web page content, accessing sensitive information, and altering data by submitting forms.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04547
CVE-2022-20765

Affected Products

Cisco Ucs Director