Cisco Cyber Vision Center Stored Cross-Site Scripting Vulnerabilities
TL;DR 📌
Cisco Cyber Vision Center has multiple stored cross-site scripting (XSS) vulnerabilities that could allow authenticated remote attackers to execute arbitrary scripts. The highest CVSS score for these vulnerabilities is 5.4, categorized as Medium severity. There are no workarounds available, and users are advised to upgrade to fixed software releases.
What happened 🕵️♂️
Multiple vulnerabilities have been identified in the web-based management interface of Cisco Cyber Vision Center. These vulnerabilities arise from insufficient validation of user-supplied input, enabling authenticated attackers to conduct XSS attacks. Successful exploitation could allow attackers to execute arbitrary scripts or access sensitive browser-based information. Specifically, exploitation of CVE-2025-20356 requires administrative access to the Sensor Explorer page, while CVE-2025-20357 requires access to the Reports page.
Affected products 🖥️
The vulnerabilities affect Cisco Cyber Vision Center, regardless of device configuration. Cisco Cyber Vision Global Center and Cisco Cyber Vision Sensors are confirmed not to be vulnerable.
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 5.2 and earlier | Migrate to a fixed release. | |
| 5.3 | Not vulnerable. | |
| 5.0 and earlier | Not vulnerable. | |
| 5.1 | Migrate to a fixed release. | |
| 5.2 | Migrate to a fixed release. | |
| 1.0 | Initial public release. | |
| Cisco Cyber Vision Center | 5.3 | 5.2 and earlier |
| Cisco Cyber Vision Center | 5.1 | 5.0 and earlier |
| Cisco Cyber Vision Center | 5.2 | 5.1 |
Workarounds 🧯
There are no workarounds that address these vulnerabilities.
Risk in context 🎯
With a CVSS score of 5.4, the risk is categorized as Medium. The vulnerabilities require authenticated access, meaning they are not directly exploitable from the internet without valid credentials. However, if exploited, they could lead to significant data exposure and compromise the integrity of the web interface.
Fast facts ⚡
- Vulnerabilities: Stored XSS in Cisco Cyber Vision Center
- CVSS Score: 5.4 (Medium)
- Exploitation: Requires authenticated access
- Workarounds: None available
- Fixed Software: Upgrades to specific versions recommended
For leadership 🧭
Executive summary. Cisco Cyber Vision Center, the management console for OT network monitoring, has two stored cross-site scripting flaws that let a logged-in user with access to the Sensor Explorer or Reports page inject scripts that later run in another user’s session. It’s medium severity and needs authenticated access, so it can wait for the next patch cycle rather than an emergency change, but it should not be left indefinitely given there’s no workaround.
Why it matters:
- Cisco Cyber Vision Center is the central console operators use to monitor industrial network sensors, so a compromised admin session there has visibility into OT asset and traffic data.
- CVE-2025-20356 needs administrative access to the Sensor Explorer page and CVE-2025-20357 needs access to the Reports page, meaning any user with those permissions can plant a persistent script for others to trigger.
- There is no workaround, so mitigation depends entirely on restricting who holds Sensor Explorer or Reports access until the affected instance is upgraded.
- Cisco Cyber Vision Global Center and the Sensors themselves are not affected, so exposure is confined to the Center’s web interface.
Now / Next / Later:
- Now: Identify every user account with access to the Sensor Explorer or Reports pages in Cyber Vision Center and confirm none of those permissions are held by untrusted or low-trust accounts.
- Next: Upgrade affected Cyber Vision Center instances (5.2 and earlier on the 5.2 train, or 5.1 and earlier depending on train) to the first fixed release identified for your version during the next change window.
- Later: Review and tighten role assignments for Sensor Explorer and Reports access as a standing control, since these pages are the confirmed injection points and no interim mitigation exists outside patching.