Cisco IE 1000 Series Switches Hit with Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting (XSS) vulnerability has been discovered in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches. The issue could allow an authenticated, remote attacker to conduct a XSS attack against a user of the interface.
The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of affected systems.
Cisco has released software updates that address this vulnerability, but there are no workarounds available. An attacker must have valid user credentials on the affected system to exploit this vulnerability.