CVE-2025-20342 - CVE House
Back to Database
Status published Medium CVE-2025-20342

Cisco Integrated Management Controller Virtual Keyboard Video Monitor (vKVM) Stored Cross-Site Scripting Vulnerability

Vulnerability Description

A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid user credentials with privileges that allow for vKVM access on the affected device. Note: The affected vKVM client is also included in Cisco UCS Manager.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-20342

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Unified Computing System (Managed), Cisco Unified Computing System (Standalone), Cisco Unified Computing System E-Series Software (UCSE)
Vulnerable Versions:
4.0(1a), 3.2(3n), 4.1(1a), 4.1(1b), 4.0(4h), 4.1(1c), 3.2(3k), 3.2(2c), 4.0(4e), 4.0(4g), 3.2(3i), 4.0(2e), 3.2(3g), 4.0(4a), 4.0(2d), 3.2(2d), 4.0(1b), 4.0(4f), 3.2(3h), 3.2(2f), 4.0(4c), 3.2(3a), 4.0(1c), 3.2(3d), 3.2(2b), 4.0(4b), 3.2(2e), 4.0(2b), 4.0(4d), 3.2(1d), 3.2(3e), 3.2(3l), 3.2(3b), 4.0(2a), 3.2(3j), 4.0(1d), 3.2(3o), 4.0(4i), 4.1(1d), 4.1(2a), 4.1(1e), 3.2(3p), 4.1(2b), 4.0(4k), 4.1(3a), 4.1(3b), 4.1(2c), 4.0(4l), 4.1(4a), 4.1(3c), 4.1(3d), 4.2(1c), 4.2(1d), 4.0(4m), 4.1(3e), 4.2(1f), 4.1(3f), 4.2(1i), 4.1(3h), 4.2(1k), 4.2(1l), 4.0(4n), 4.2(1m), 4.1(3i), 4.2(2a), 4.2(1n), 4.1(3j), 4.2(2c), 4.2(2d), 4.2(3b), 4.1(3k), 4.0(4o), 4.2(2e), 4.2(3d), 4.2(3e), 4.2(3g), 4.1(3l), 4.3(2b), 4.2(3h), 4.2(3i), 4.3(2c), 4.1(3m), 4.3(2e), 4.3(3a), 4.2(3j), 4.3(3c), 4.3(4a), 4.2(3k), 4.3(4b), 4.3(4c), 4.2(3l), 4.3(4d), 4.3(2f), 4.2(3m), 4.3(5a), 4.3(4e), 4.1(3n), 4.3(4f), 4.2(3n), 4.3(5c), 4.2(3o), 4.3(5d), 4.3(5e), 2.0(1a), 4.0(2g), 2.0(13f), 3.0(4n), 2.0(3e)1, 3.0(3e), 2.0(8h), 2.0(10g), 3.1(2i), 3.0(3c), 3.0(4m), 3.1(1d), 3.0(3a), 3.0(1d), 2.0(9o), 2.0(13n), 2.0(13q), 2.0(3j)1, 4.0(2c), 2.0(9n), 4.0(1e), 2.0(13o), 2.0(6f), 2.0(10c), 2.0(8d), 2.0(9m), 4.0(2h), 3.0(4j), 2.0(10i), 3.0(3f), 2.0(10l), 2.0(12e), 2.0(12i), 2.0(10h), 2.0(13e), 3.0(4k), 2.0(10b), 2.0(6d), 2.0(12b), 2.0(12h), 2.0(10f), 3.0(4l), 4.0(1h), 4.0(2l), 2.0(3i), 2.0(3f)3, 3.0(4a), 2.0(13p), 2.0(9l), 2.0(12g), 2.0(12c), 2.0(12f), 2.0(13k), 3.0(3b), 2.0(1b), 3.1(3g), 2.0(4c), 4.0(1.240), 2.0(12d), 4.0(2f), 4.0(1g), 3.0(4d), 3.0(2b), 2.0(3d)2, 2.0(3d)1, 2.0(9f), 2.0(13h), 3.0(4e), 2.0(8g), 4.0(2i), 2.0(10e), 2.0(13i), 2.0(9c), 2.0(4c)1, 3.0(1c), 2.0(8e), 2.0(9e), 2.0(9p), 3.1(3i), 3.0(4i), 2.0(10k), 3.0(4o), 3.1(3c), 3.1(2d), 3.1(3a), 3.1(3j), 4.1(1f), 3.0(4p), 3.1(3d), 3.1(2g), 3.1(2c), 3.1(2e), 3.1(3b), 3.1(2b), 3.1(3h), 3.0(4q), 4.1(1g), 3.0(4r), 4.0(2n), 4.1(1h), 3.1(3k), 4.0(2o), 4.1(2d), 4.0(2p), 4.1(2e), 4.1(2f), 3.0(4s), 4.0(2q), 4.0(2r), 4.1(2g), 4.1(2h), 4.1(2j), 4.1(2k), 4.2(2f), 4.2(2g), 4.3(1.230097), 4.2(1e), 4.2(1b), 4.2(1j), 4.2(1a), 4.2(1g), 4.3(1.230124), 4.1(2l), 4.3(1.230138), 4.3(2.230207), 4.3(2.230270), 4.1(2m), 4.3(2.240002), 4.3(3.240022), 4.3(2.240009), 4.3(3.240043), 4.3(4.240142), 4.3(2.240037), 4.3(2.240053), 4.3(4.240152), 4.3(2.240077), 4.3(4.242028), 4.3(4.241063), 4.3(4.242038), 4.3(2.240090), 4.3(5.240021), 4.3(2.240107), 4.3(4.242066), 4.3(2.250016), 4.3(2.250021), 4.3(2.250022), 4.3(2.250037), 4.3(2.250045), 4.3(4.252001), 3.2.7, 3.2.6, 3.2.4, 3.2.10, 3.2.2, 3.2.3, 2.4.0, 3.2.1, 3.2.11.1, 3.2.8, 3.1.1, 3.0.2, 2.1.0, 2.2.2, 3.1.2, 3.0.1, 2.3.2, 2.3.5, 2.2.1, 3.1.4, 2.4.1, 2.3.1, 3.1.3, 2.3.3, 2.4.2, 3.1.5, 3.1.0, 2.0.0, 3.2.11.3, 3.2.11.5, 3.2.12.2, 3.2.13.6, 3.2.14, 4.11.1, 3.2.15, 4.12.1, 3.2.15.3, 4.12.2, 3.2.16.1, 2.02, 4.00

Timeline

Official Publish: August 27th, 2025
Last Modified: August 27th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)