QID 316913
Date Published: 2021-04-05
QID 316913: Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family Stored Cross-Site Scripting Vulnerability(cisco-sa-ewlc-xss-cAfMtCzv)
A vulnerability in the web-based management interface of Cisco IOS XE Wireless Controller software
for the Catalyst 9000 Family of switches could allow an authenticated, remote attacker to conduct
a cross-site scripting (XSS) attack against another user of the
web-based management interface of an affected device.
Affected Products
The following Cisco products if they were running a vulnerable release of Cisco IOS XE Software:
Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches
Catalyst 9800 Series Wireless Controllers
Embedded Wireless Controller on Catalyst Access Points
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to execute arbitrary script code in the context
of the affected interface or to access sensitive, browser-based information.
Customers are advised to refer to cisco-sa-ewlc-xss-cAfMtCzv for more information.
- cisco-sa-ewlc-xss-cAfMtCzv -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewlc-xss-cAfMtCzv
CVEs related to QID 316913
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ewlc-xss-cAfMtCzv |
|