Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability

MonitorCVSS 5.4cisco-sa-ie1k-NgXUFF52Aug 19, 2026
CiscoManufacturing
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

A stored cross-site scripting (XSS) vulnerability exists in the web-based management interface of Cisco IE 1000 Series Switches due to insufficient input validation. An authenticated attacker can inject malicious JavaScript code into specific pages of the interface. When another authorized user accesses those pages, the injected script executes in their browser session, potentially allowing credential theft or unauthorized switch configuration changes. Cisco has released patched firmware to address this issue.

What this means
What could happen
An authenticated attacker could inject malicious code into the switch's web interface that executes when other authorized users access it, potentially allowing them to capture credentials or perform unauthorized configuration changes to your network switches.
Who's at risk
Manufacturing facilities and utilities using Cisco Industrial Ethernet 1000 Series Switches for critical network infrastructure. This affects any organization with engineers or IT staff who use the web-based management interface to configure and monitor these switches.
How it could be exploited
An attacker with valid credentials logs into the IE 1000 web management interface and injects JavaScript code into input fields on specific pages. When another authorized user (such as an engineer or IT administrator) accesses those same pages, the malicious script runs in their browser session, potentially allowing the attacker to steal session tokens, capture keystrokes, or trigger unauthorized actions on the switch.
Prerequisites
  • Valid user account credentials for the IE 1000 switch web management interface
  • Network access to the switch's management interface (typically HTTP/HTTPS, port 80 or 443)
  • Another user must access the compromised page in the interface for the attack to execute
Requires valid credentialsRequires user interaction (victim must visit crafted page)Affects administrative/engineering interfacesLow CVSS score but targets authenticated administrators
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
Cisco Industrial Ethernet 1000 Series Switches Stored1.1 through 1.9.5Fix available
Remediation & Mitigation
0/4
Do now
0/3
HARDENINGRestrict access to the IE 1000 switch web management interface to authorized engineering/IT personnel only using firewall rules or network segmentation
WORKAROUNDDisable the web management interface on IE 1000 switches if not actively needed; use command-line management or SNMP instead
HARDENINGChange any default or shared administrative credentials on all IE 1000 switches
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Cisco IE 1000 Series Switches to firmware version 1.9.6 or later
API: /api/v1/advisories/ae87dabe-7e19-4cbd-bb65-95d42d058b77

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability | CVSS 5.4 - OTPulse