Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting (XSS) vulnerability exists in the web-based management interface of Cisco IE 1000 Series Switches due to insufficient input validation. An authenticated attacker can inject malicious JavaScript code into specific pages of the interface. When another authorized user accesses those pages, the injected script executes in their browser session, potentially allowing credential theft or unauthorized switch configuration changes. Cisco has released patched firmware to address this issue.
- Valid user account credentials for the IE 1000 switch web management interface
- Network access to the switch's management interface (typically HTTP/HTTPS, port 80 or 443)
- Another user must access the compromised page in the interface for the attack to execute
Patching may require device reboot — plan for process interruption
/api/v1/advisories/ae87dabe-7e19-4cbd-bb65-95d42d058b77Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.