CVE-2023-20188 is a stored cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Small Business 200, 300, and 500 Series Switches. An authenticated, remote attacker can exploit this by injecting malicious HTML/script into user-supplied input, which is then executed when another user views the affected page. This medium-severity vulnerability (CVSS 4.8) requires valid credentials and user interaction, potentially leading to arbitrary script execution or sensitive information disclosure. There are no known exploits in the wild, no public exploit code, and minimal community discussion, indicating low current exploitation risk. Cisco has not released patches for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.11.02CPE matchmatch criteria | cpe:2.3:o:cisco:sf200-24_firmware:1.4.11.02:*:*:*:*:*:*:* | ||
1.4.11.02CPE matchmatch criteria | cpe:2.3:o:cisco:sf200-24fp_firmware:1.4.11.02:*:*:*:*:*:*:* | ||
1.4.11.02CPE matchmatch criteria | cpe:2.3:o:cisco:sf200-24p_firmware:1.4.11.02:*:*:*:*:*:*:* | ||
1.4.11.02CPE matchmatch criteria | cpe:2.3:o:cisco:sf200-48_firmware:1.4.11.02:*:*:*:*:*:*:* | ||
1.4.11.02CPE matchmatch criteria | cpe:2.3:o:cisco:sf200-48p_firmware:1.4.11.02:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.