VDB

CVE-2025-20123

CVE-2025-20123 PUBLISHED CVSS 4.800000190734863 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users of the interface of an affected system. These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by inserting malicious data into specific data fields in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid administrative credentials. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

EPSS 0.09% · 25.6th percentile

Risk Scores

CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.09%
25.6th percentile

Affected Products

VendorProductVersions
CiscoCisco Crosswork Network Change Automation2.0.1, 5.0.0, 3.0.0
ciscocrosswork_network_controller6.0.0, 7.0.0, 5.0.0

Exploit Intelligence

Timeline

  • Oct 10, 2024 CVE ID Reserved
  • Jan 8, 2025 CVE Published
  • Jan 8, 2025 PoC Published
  • Jan 8, 2025 PoC Published
  • Jan 8, 2025 PoC Published
  • Jan 8, 2025 PoC Published
  • Jan 8, 2025 CVE Updated
  • Jan 9, 2025 EPSS Score
  • Jan 20, 2025 Coalition ESS Score
  • Jan 25, 2025 EPSS Score
  • Feb 9, 2025 EPSS Score
  • Feb 25, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›