CVE-2025-20317

HIGH

Cisco IMC - Open Redirect

Title source: llm
STIX 2.1

Description

A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious webpage and potentially capture user credentials. Note: The affected vKVM client is also included in Cisco UCS Manager.

Scores

CVSS v3 7.1
EPSS 0.0003
EPSS Percentile 9.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (50)
Cisco/Cisco Unified Computing System (Managed) 3.2(1d)
Cisco/Cisco Unified Computing System (Managed) 3.2(2b)
Cisco/Cisco Unified Computing System (Managed) 3.2(2c)
Cisco/Cisco Unified Computing System (Managed) 3.2(2d)
Cisco/Cisco Unified Computing System (Managed) 3.2(2e)
Cisco/Cisco Unified Computing System (Managed) 3.2(2f)
Cisco/Cisco Unified Computing System (Managed) 3.2(3a)
Cisco/Cisco Unified Computing System (Managed) 3.2(3b)
Cisco/Cisco Unified Computing System (Managed) 3.2(3d)
Cisco/Cisco Unified Computing System (Managed) 3.2(3e)
... and 40 more
Published Aug 27, 2025
Tracked Since Feb 18, 2026