High
CVE-2023-20037 CVSS:5.4
Cisco Industrial Network Director is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVE-2023-20038 CVSS:8.8
Cisco Industrial Network Director could allow a local authenticated attacker to obtain sensitive information, caused by a the storage of a static key value in the application. By utilize cryptographic attack techniques, an attacker could exploit this vulnerability to decrypt local data or access remote systems monitored by Cisco IND.
Cisco
Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.