CVE-2023-20228 - CVE House
Back to Database
Status published Medium CVE-2023-20228

A vulnerability in the web-based management interface of Cisco Integrated...

Vulnerability Description

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-20228

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Identity Services Engine Software, Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Vulnerable Versions:
3.1(1d), 3.1(2b), 3.1(2c), 3.1(2d), 3.1(2e), 3.1(2g), 3.1(2i), 3.1(3a), 3.1(3b), 3.1(3c), 3.1(3d), 3.1(3g), 3.1(3h), 3.1(3i), 3.1(3j), 3.1(3k), 4.0(1.240), 4.0(1a), 4.0(1b), 4.0(1c), 4.0(1d), 4.0(1e), 4.0(1g), 4.0(1h), 4.0(2c), 4.0(2d), 4.0(2f), 4.0(2g), 4.0(2h), 4.0(2i), 4.0(2l), 4.0(2n), 4.0(4b), 4.0(4c), 4.0(4d), 4.0(4e), 4.0(4f), 4.0(4h), 4.0(4i), 4.0(4k), 4.0(4l), 4.0(4m), 4.0(2o), 4.0(2p), 4.0(4n), 4.0(2q), 4.0(2r), 4.1(1c), 4.1(1d), 4.1(1f), 4.1(1g), 4.1(2a), 4.1(1h), 4.1(2b), 4.1(2f), 4.1(2e), 4.1(3b), 4.1(2d), 4.1(3c), 4.1(3d), 4.1(2g), 4.1(3f), 4.1(2h), 4.1(2j), 4.1(2k), 4.1(2l), 4.1(3h), 4.1(3i), 4.1(3l), 4.2(1a), 4.2(1b), 4.2(1c), 4.2(1e), 4.2(1f), 4.2(1g), 4.2(1i), 4.2(1j), 4.2(2a), 4.2(2f), 4.2(2g), 4.2(3b), 4.2(3d), 4.2(3e), 4.3(1.230097), 4.3(1.230124), 4.3(1.230138), 2.1.0, 2.4.0, 2.4.1, 2.4.2, 3.2.1, 3.2.2, 3.2.3, 3.2.4, 3.2.6, 3.2.7, 3.2.10, 3.2.11.1, 3.2.8, 3.2.11.3, 3.2.11.5, 3.2.12.2, 3.2.13.6, 3.2.14, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.0, 3.0.1, 3.0.2, 2.3.1, 2.3.2, 2.3.3, 2.3.5, 2.2.1, 2.2.2, 2.0.0, 2.10, 3.06, 3.02, 4.11.1

Timeline

Official Publish: August 16th, 2023
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)