CVE-2025-20296: Cisco UCS Manager Software Stored Software Stored Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious data into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must be a member of the Administrator or AAA Administrator role.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20296?
CVE-2025-20296 is classified as a high severity vulnerability due to its potential for allowing stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-20296?
To fix CVE-2025-20296, ensure you are using the latest version of Cisco UCS Manager Software which contains the necessary security patches.
Who is affected by CVE-2025-20296?
Users of the Cisco UCS Manager Software are affected by CVE-2025-20296 if they have an outdated version of the software.
What is the impact of CVE-2025-20296?
The impact of CVE-2025-20296 includes the potential for attackers to execute arbitrary scripts in the context of an authenticated user's session.
Is CVE-2025-20296 exploited in the wild?
As of the latest reports, there have been no widely reported exploits of CVE-2025-20296 in the wild, but it is critical to address it promptly.