CVE-2025-20317
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-08-27
Last updated on: 2025-08-29
Assigner: Cisco Systems, Inc.
Description
Description
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website.
This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious webpage and potentially capture user credentials.
Note: The affected vKVM client is also included in Cisco UCS Manager.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| cisco | secure_network_analytics_appliance | * |
| cisco | secure_malware_analytics_appliance | * |
| cisco | secure_network_server_appliance | * |
| cisco | ucs_b-series_servers | * |
| cisco | ucs_e-series_servers | * |
| cisco | catalyst_8300_series_edge_ucpe | 4.18.1 |
| cisco | ucs_manager_software | 4.2(3p) |
| cisco | ucs_c-series_servers | * |
| cisco | secure_endpoint_private_cloud_appliance | 4.2.5 |
| cisco | ucs_x-series_servers | * |
| cisco | ucs_manager_software | 4.3(6a) |
| cisco | secure_firewall_management_center_appliance | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-601 | The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect. |