Description
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious webpage and potentially capture user credentials. Note: The affected vKVM client is also included in Cisco UCS Manager.
Scores
CVSS v3
7.1
EPSS
0.0003
EPSS Percentile
9.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (50)
Cisco/Cisco Unified Computing System (Managed)
3.2(1d)
Cisco/Cisco Unified Computing System (Managed)
3.2(2b)
Cisco/Cisco Unified Computing System (Managed)
3.2(2c)
Cisco/Cisco Unified Computing System (Managed)
3.2(2d)
Cisco/Cisco Unified Computing System (Managed)
3.2(2e)
Cisco/Cisco Unified Computing System (Managed)
3.2(2f)
Cisco/Cisco Unified Computing System (Managed)
3.2(3a)
Cisco/Cisco Unified Computing System (Managed)
3.2(3b)
Cisco/Cisco Unified Computing System (Managed)
3.2(3d)
Cisco/Cisco Unified Computing System (Managed)
3.2(3e)
... and 40 more
Published
Aug 27, 2025
Tracked Since
Feb 18, 2026