CVE-2023-20228 is a cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC), stemming from insufficient user input validation. An unauthenticated, remote attacker could exploit this by tricking a user into clicking a crafted link. A successful attack could lead to arbitrary script execution in the user's browser or access to sensitive browser-based information. This vulnerability has a CVSS score of 6.1 (Medium) and is not known to be actively exploited, nor is public exploit code or significant community discussion available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2, < 3.2.15.1CPE matchmatch criteria | cpe:2.3:o:cisco:encs_5100_firmware:*:*:*:*:*:*:*:* | ||
>= 3.2, < 3.2.15.1CPE matchmatch criteria | cpe:2.3:o:cisco:encs_5400_firmware:*:*:*:*:*:*:*:* | ||
>= 4.2, < 4.3.2.230207CPE matchmatch criteria | cpe:2.3:o:cisco:ucs_c220_m5_rack_server_firmware:*:*:*:*:*:*:*:* | ||
< 3.2.15.1CPE matchmatch criteria | cpe:2.3:o:cisco:ucs_e160s_m3_firmware:*:*:*:*:*:*:*:* | ||
< 3.2.15.1CPE matchmatch criteria | cpe:2.3:o:cisco:ucs_e180d_m3_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.