QID 317415

QID 317415: Cisco Integrated Management Controller (CIMC) Cross-Site Scripting Vulnerability (cisco-sa-cimc-xss-UMYtYEtr)

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

Affected Versions:
Cisco UCS C-Series M4 Rack Server
version 4.1 and earlier
Cisco UCS C-Series M5 Rack Server
Version 4.2(3h)
4.3 prior to version 4.3.2.230207
Cisco UCS E-Series M3 Server
Prior to version 3.2.15.1
Cisco UCS S-Series Storage Server
4.2 prior to 4.2(3h)
4.3 prior 4.3.2.230270
Note: This QID does not checks for 5000 Series Enterprise Network Compute System (ENCS)

QID Detection Logic (Authenticated):
The check matches Cisco cimc version retrieved using "show cimc detail " command.

A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-cimc-xss-UMYtYEtr for more information.

    CVEs related to QID 317415

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-cimc-xss-UMYtYEtr URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-UMYtYEtr