CVE-2026-20232
Received Received - Intake

Stored XSS in Cisco Industrial Ethernet 1000 Series Switches

Vulnerability report for CVE-2026-20232, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of another user. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cisco industrial_ethernet_1000_series_switches *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-80 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches. It allows an authenticated remote attacker to inject malicious code into specific pages of the interface. When another user accesses the affected pages, the injected code executes in their browser context.

Detection Guidance

Detecting this vulnerability requires checking for XSS vulnerabilities in the web interface of Cisco IE 1000 Series Switches. Inspect web interface pages for improper input validation by reviewing HTML forms and parameters. Use tools like Burp Suite or OWASP ZAP to test for stored XSS vulnerabilities. Monitor network traffic for suspicious script injections in HTTP responses.

Impact Analysis

An attacker could use this vulnerability to execute arbitrary script code in the context of another user's session. This could lead to unauthorized actions being performed, theft of session cookies, or other malicious activities within the web interface.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized script execution in user interfaces. Stored XSS attacks may lead to data breaches or unauthorized access, violating confidentiality requirements under these regulations. Affected organizations must address this issue to maintain compliance.

Mitigation Strategies

Immediately upgrade to the fixed software releases provided by Cisco for IE 1000 Series Switches. Ensure all users with access to the web interface use strong credentials and follow least privilege principles. Disable unnecessary services and restrict access to the management interface via network segmentation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20232. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart