QID 377893
Date Published: 2023-04-25
QID 377893: Cisco Industrial Network Director Cross-Site Scripting (XSS) Vulnerability (cisco-sa-ind-fZyVjJtG) (CVE-2023-20037)
This vulnerability is due to improper validation of content that is submitted to the affected application. An attacker could exploit this vulnerability by sending malicious HTTPS requests to an affected system
Affected Products
Cisco IND Release 1 and prior to 1.7.0
QID Detection Logic (authenticated):
The QID matches version of Cisco Industrial Network Director using registry "HKEY_LOCAL_MACHINE\SOFTWARE\Cisco\Cisco Industrial Network Director"
A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. (P)
Solution
Customers are advised to refer to cisco-sa-ind-fZyVjJtG
Vendor References
- cisco-sa-ind-fZyVjJtG -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ind-fZyVjJtG
CVEs related to QID 377893
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ind-fZyVjJtG |
|