Description
A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link and access a specific page. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published: 2020-01-26
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-24392 A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link and access a specific page. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
History

Fri, 15 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Sf350-48 Sf350-48 Firmware Sf350-48mp Sf350-48mp Firmware Sf350-48p Sf350-48p Firmware Sf550x-24 Sf550x-24 Firmware Sf550x-24p Sf550x-24p Firmware Sf550x-48 Sf550x-48 Firmware Sf550x-48mp Sf550x-48mp Firmware Sf550x-48p Sf550x-48p Firmware Sg250-08 Sg250-08 Firmware Sg250-08hp Sg250-08hp Firmware Sg250-10p Sg250-10p Firmware Sg250-18 Sg250-18 Firmware Sg250-24 Sg250-24 Firmware Sg250-24p Sg250-24p Firmware Sg250-26 Sg250-26 Firmware Sg250-26hp Sg250-26hp Firmware Sg250-26p Sg250-26p Firmware Sg250-48 Sg250-48 Firmware Sg250-48hp Sg250-48hp Firmware Sg250-50 Sg250-50 Firmware Sg250-50hp Sg250-50hp Firmware Sg250-50p Sg250-50p Firmware Sg250x-24 Sg250x-24 Firmware Sg250x-24p Sg250x-24p Firmware Sg250x-48 Sg250x-48 Firmware Sg250x-48p Sg250x-48p Firmware Sg350-10 Sg350-10 Firmware Sg350-10mp Sg350-10mp Firmware Sg350-10p Sg350-10p Firmware Sg350-28 Sg350-28 Firmware Sg350-28mp Sg350-28mp Firmware Sg350-28p Sg350-28p Firmware Sg355-10mp Sg355-10mp Firmware Sg550x-24 Sg550x-24 Firmware Sg550x-24mp Sg550x-24mp Firmware Sg550x-24mpp Sg550x-24mpp Firmware Sg550x-24p Sg550x-24p Firmware Sg550x-48 Sg550x-48 Firmware Sg550x-48mp Sg550x-48mp Firmware Sg550x-48p Sg550x-48p Firmware Sx550x-12ft Sx550x-12ft Firmware Sx550x-16ft Sx550x-16ft Firmware Sx550x-24 Sx550x-24 Firmware Sx550x-24ft Sx550x-24ft Firmware Sx550x-52 Sx550x-52 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-15T17:45:38.991Z

Reserved: 2019-12-12T00:00:00.000Z

Link: CVE-2020-3121

cve-icon Vulnrichment

Updated: 2024-08-04T07:24:00.540Z

cve-icon NVD

Status : Modified

Published: 2020-01-26T05:15:17.397

Modified: 2024-11-21T05:30:22.217

Link: CVE-2020-3121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses