PT-2023-4590 · Cisco · Cisco Integrated Management Controller

Mohamed Benkadour

·

Published

2023-08-16

·

Updated

2024-01-25

·

CVE-2023-20228

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Integrated Management Controller (IMC) (affected versions not specified)
Description The issue exists due to insufficient validation of user input in the web-based management interface. An attacker could exploit this by persuading a user to click a crafted link, potentially allowing the execution of arbitrary script code in the browser of the targeted user or access to sensitive, browser-based information. This could enable a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-04997
CVE-2023-20228

Affected Products

Cisco Integrated Management Controller