CVE-2022-20635: Cisco Security Manager Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20635?
CVE-2022-20635 has a high severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2022-20635?
To fix CVE-2022-20635, update your Cisco Security Manager to a version beyond 4.24 that addresses this vulnerability.
What types of attacks are facilitated by CVE-2022-20635?
CVE-2022-20635 enables unauthenticated remote attackers to conduct cross-site scripting attacks.
Who is affected by CVE-2022-20635?
Users of Cisco Security Manager versions prior to 4.24 are affected by CVE-2022-20635.
What are the implications of exploiting CVE-2022-20635?
Exploiting CVE-2022-20635 could allow attackers to execute arbitrary scripts in the context of the user's session, leading to data theft or hijacked user sessions.