Cisco Security Advisory
Follow
Cisco Cyber Vision Center Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in Cisco Cyber Vision Center's web interface can lead to cross-site scripting (XSS) attacks. These issues stem from insufficient validation of user-supplied input within the management interface. An attacker could exploit these by injecting malicious code into specific pages. Successful exploitation allows the attacker to run arbitrary script code in the context of the interface. They could also gain access to sensitive browser-based information. For CVE-2025-20356, administrative access to the Sensor Explorer page is required. By default, Admin and Product roles, and custom users with Sensors page access, are affected. For CVE-2025-20357, administrative access to the Reports page is the prerequisite. This affects all default user roles and custom users with Reports page access. Cisco has released software updates to fix these vulnerabilities. There are no temporary workarounds available.