PT-2022-3792 · Cisco · Cisco Catalyst 2940 Series Switches

Imaoka Ryo

·

Published

2022-06-02

·

Updated

2024-08-03

·

CVE-2022-31734

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Catalyst 2940 Series Switches versions prior to 12.2(50)SY
Description The issue exists due to inadequate protection of the web page structure, allowing for a reflected cross-site scripting attack. This can enable a remote attacker to execute an arbitrary script on the user's web browser. The affected devices have been retired since January 2015.
Recommendations For versions prior to 12.2(50)SY, update to version 12.2(50)SY or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface of the Cisco Catalyst 2940 Series Switches to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-04586
CVE-2022-31734

Affected Products

Cisco Catalyst 2940 Series Switches