CVE-2025-20317
BaseFortify
Publication date: 2025-08-27
Last updated on: 2025-08-29
Assigner: Cisco Systems, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| cisco | secure_network_analytics_appliance | * |
| cisco | secure_malware_analytics_appliance | * |
| cisco | secure_network_server_appliance | * |
| cisco | ucs_b-series_servers | * |
| cisco | ucs_e-series_servers | * |
| cisco | catalyst_8300_series_edge_ucpe | 4.18.1 |
| cisco | ucs_manager_software | 4.2(3p) |
| cisco | ucs_c-series_servers | * |
| cisco | secure_endpoint_private_cloud_appliance | 4.2.5 |
| cisco | ucs_x-series_servers | * |
| cisco | ucs_manager_software | 4.3(6a) |
| cisco | secure_firewall_management_center_appliance | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-601 | The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an open redirect flaw in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC), including the vKVM client in Cisco UCS Manager. It occurs because the system does not properly verify vKVM endpoints. An unauthenticated remote attacker can craft a malicious link that, when clicked by a user, redirects them to a malicious website. This redirection can lead to capturing user credentials. [1]
How can this vulnerability impact me? :
If exploited, this vulnerability can redirect users to malicious websites where attackers may steal user credentials. This can lead to unauthorized access and potential compromise of user accounts or systems. Since the attacker does not need to be authenticated and only needs to persuade a user to click a crafted link, the risk is significant. [1]
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, immediately upgrade affected Cisco Integrated Management Controller (IMC) and Cisco UCS Manager software to the fixed versions listed by Cisco. There are no workarounds available. For specific products, apply the corresponding software updates or firmware upgrades as detailed by Cisco, such as upgrading to Cisco NFVIS 4.18.1 for Catalyst 8300 Series Edge uCPE, UCS Manager Software versions 4.2(3p) or later, and other fixed releases for UCS B-Series, C-Series, E-Series, and X-Series servers. For Cisco appliances based on UCS C-Series Servers, perform direct IMC software upgrades or apply specific firmware updates or hotfixes as required. Customers with service contracts should obtain fixes through normal update channels, while those without contracts should contact Cisco TAC for assistance. [1]