Cisco Catalyst Center Cross-Site Scripting Vulnerability
TL;DR 📌
A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Catalyst Center. This vulnerability could allow an unauthenticated remote attacker to execute arbitrary script code in the context of the affected interface. Cisco has released fixed software to address this issue, but there are no workarounds available.
What happened 🕵️♂️
A vulnerability in the Cisco Catalyst Center’s web-based management interface allows an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. This is due to insufficient validation of user input, enabling an attacker to exploit the vulnerability by persuading a user to click a crafted link. A successful exploit could lead to the execution of arbitrary script code or access to sensitive browser-based information.
Affected products 🖥️
The vulnerability affects all versions of Cisco Catalyst Center, specifically those running versions 2.3.7 and earlier. Cisco Catalyst Center Virtual Appliance is confirmed not to be affected.
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 2.3.7 and earlier | 2.3.7.10 | |
| 3.1 | Not affected | |
| 1.0 | Initial public release. | |
| Cisco Catalyst Center | 2.3.7.10 | 2.3.7 and earlier |
Workarounds 🧯
There are no workarounds available to mitigate this vulnerability.
Risk in context 🎯
With a CVSS score of 6.1, this vulnerability is rated as Medium severity. The risk arises from the potential for an attacker to exploit the XSS vulnerability without authentication, making it easier for them to target users of the web interface. Immediate action is recommended to upgrade to the fixed software to mitigate this risk.
Fast facts ⚡
- Vulnerability Type: Cross-Site Scripting (XSS)
- CVSS Score: 6.1 (Medium)
- Exploitation Potential: Unauthenticated remote access
- Fixed Software: 2.3.7.10 for affected versions
- Workarounds: None available
For leadership 🧭
Executive summary. Cisco Catalyst Center, used to manage network infrastructure, has a web interface flaw that lets an outsider run malicious script in an administrator’s browser simply by getting them to click a link, potentially exposing session data or browser-held credentials. Because there is no workaround, this should be scheduled for patching in the next available maintenance window rather than left open indefinitely.
Why it matters:
- The flaw sits in the web-based management interface of Catalyst Center, the console used to administer network devices, so a successful attack targets the people with the most privileged access to your network fabric.
- No authentication is required to trigger the attack; it only takes a crafted link and one click from a logged-in interface user.
- There are no workarounds, so the only mitigation is upgrading affected versions (2.3.7 and earlier) to the fixed release.
- Cisco Catalyst Center Virtual Appliance deployments are not affected, which narrows the scope for organisations running that variant.
Now / Next / Later:
- Now: Identify every Cisco Catalyst Center deployment on-premises (excluding Virtual Appliance, which is unaffected) and confirm which are running 2.3.7 or earlier.
- Next: Upgrade affected instances to 2.3.7.10 or later during your next change window, since no workaround exists to bridge the gap.
- Later: Add Catalyst Center’s web interface to routine patch tracking and remind administrators to avoid clicking unsolicited links while authenticated to network management consoles.