Cisco Integrated Management Controller Virtual Keyboard Video Monitor Stored Cross-Site Scripting Vulnerability
TL;DR 📌
A stored cross-site scripting (XSS) vulnerability has been identified in the Cisco Integrated Management Controller’s Virtual Keyboard Video Monitor (vKVM). This medium-severity issue allows authenticated attackers to execute arbitrary scripts in the context of the affected interface. Cisco has released software updates to address this vulnerability, but no workarounds are available.
What happened 🕵️♂️
A vulnerability in the vKVM connection handling of Cisco’s Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored XSS attack. This vulnerability arises from insufficient validation of user-supplied input in the web-based management interface. An attacker could exploit this by injecting malicious code into specific data fields, potentially executing arbitrary script code or accessing sensitive browser-based information.
Affected products 🖥️
The following Cisco products are affected if they are running a vulnerable software release:
- Catalyst 8300 Series Edge uCPE
- Cisco UCS Manager Software
- UCS B-Series Blade Servers
- UCS C-Series M6, M7, and M8 Rack Servers
- UCS E-Series Servers M6
- UCS X-Series Modular System
Additionally, various Cisco appliances based on preconfigured versions of the UCS C-Series Servers are also affected.
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 4.18 and earlier | 4.18.1 | |
| 4.1 and earlier | Migrate to a fixed release. | |
| 4.2 | 4.2(3p) | |
| 4.3 | 4.3(6a) | |
| 6.0 | Not vulnerable. | |
| 4.2 | 4.2(3o) | |
| 4.3 | 4.3(5c) | |
| 4.2 | 4.2(3l) | |
| 5.1 | Migrate to a fixed release. | |
| 5.2 | Migrate to a fixed release. | |
| 5.3 | 5.3(0.250001) | |
| 5.4 | Not vulnerable. | |
| 5.0 | 5.0(4i) | |
| 4.3 | 4.3(5.250001) | |
| 4.15 and earlier | 4.15.2 | |
| 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available for this vulnerability.
Risk in context 🎯
The highest CVSS score for this vulnerability is 5.4, which is classified as Medium severity. The risk is primarily driven by the requirement for valid user credentials, which limits exposure to authenticated users. However, successful exploitation could lead to unauthorized access to sensitive information and potentially compromise the integrity of the affected systems.
Fast facts ⚡
- Vulnerability Type: Stored Cross-Site Scripting (XSS)
- CVSS Score: 5.4 (Medium)
- Exploitation: Requires valid user credentials
- Workarounds: None available
- Fixed Software: Updates available for affected products
For leadership 🧭
Executive summary. Cisco IMC’s remote console (vKVM) can be used by a logged-in, low-privilege user to inject script that later executes in another administrator’s browser session, potentially exposing session data or interface control. There is no workaround, so patching UCS management firmware to the fixed release for your train should be scheduled at the next available window rather than left indefinitely.
Why it matters:
- The flaw sits in the vKVM connection handling of Cisco IMC, the web-based console used to manage UCS blade, rack and modular servers remotely.
- Exploitation only requires low-privileged authenticated access, meaning any account with console access - not just full administrators - could inject the malicious script.
- A successful attack runs script in the context of the management interface, which could let an attacker read sensitive data visible to other users of that same web console, including higher-privileged operators.
- No workaround exists, so exposure persists on unpatched systems until the affected UCS Manager, C-Series, B-Series, E-Series or X-Series software is upgraded.
Now / Next / Later:
- Now: Identify every Cisco IMC/UCS Manager instance in your estate and check its running release against the fixed-release table to see which trains need upgrading.
- Next: Schedule upgrades of affected UCS Manager, B-/C-/E-/X-Series and Catalyst 8300 uCPE firmware to the first fixed release listed for each train during your next maintenance window, since no interim workaround exists.
- Later: Review who holds low-privilege accounts with vKVM access on IMC-managed systems and tighten console account provisioning so that fewer users can reach the vulnerable interface by default.