CVE-2025-20116

MEDIUM

Cisco Application Policy Infrastructure Controller - Authenticated Stored Cross-Site Scripting in Web UI

Title source: llm
STIX 2.1

Description

A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper input validation in the web UI. An authenticated attacker could exploit this vulnerability by injecting malicious code into specific pages of the web UI. A successful exploit could allow the attacker to execute arbitrary script code in the context of the web UI or access sensitive, browser-based information.

Scores

CVSS v3 4.8
EPSS 0.0007
EPSS Percentile 20.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (50)
cisco/application_policy_infrastructure_controller 3.2\(1l\)
cisco/application_policy_infrastructure_controller 3.2\(1m\)
cisco/application_policy_infrastructure_controller 3.2\(2l\)
cisco/application_policy_infrastructure_controller 3.2\(2o\)
cisco/application_policy_infrastructure_controller 3.2\(3i\)
cisco/application_policy_infrastructure_controller 3.2\(3j\)
cisco/application_policy_infrastructure_controller 3.2\(3n\)
cisco/application_policy_infrastructure_controller 3.2\(3o\)
cisco/application_policy_infrastructure_controller 3.2\(3r\)
cisco/application_policy_infrastructure_controller 3.2\(3s\)
... and 40 more
Published Feb 26, 2025
Tracked Since Feb 18, 2026