Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196335 vulns · 36/41 feeds (7d)
← Back to list
5.4
CVE-2026-20232
Cisco · Cisco Industrial Ethernet Switches

Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability

Description

A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of another user. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.

Affected Products

VendorProductVersions
CiscoCisco Industrial Ethernet Switches1.1, 1.2, 1.8.0, 1.8.2, 1.7.0, 1.3, 1.9.1, 1.6, 1.8.1, 1.9.2, 1.9.2a, 1.9.3, 1.9.4, 1.9.5

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
cisindustrial ethernet switchescert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ie1k-NgXUFF52

Related News (2 articles)

Tier B
BSI Advisories3d ago
[NEU] [mittel] Cisco Industrial Ethernet 1000 Series Switches: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-20232 | Cisco Industrial Ethernet Switches up to 1.9.5 web-based management interface cross site scripting
→ No new info (linked only)
CVSS 3.15.4 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-80
PublishedAug 19, 2026
Last enriched4d ago
Trending Score21
Source articles2
Independent2
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20338
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 30
HIGHCVE-2026-20337
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 30
HIGHCVE-2026-20320
CVE-2026-20320: A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote
Trending: 29
MEDIUMCVE-2026-20302
Cisco RoomOS Stack Overflow Vulnerability
Trending: 15
CRITICALCVE-2026-20303
Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
Trending: 15

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 19, 2026
Discovered by ZDM
Aug 19, 2026