Cisco Security Update – 27 April 2023

Cisco has released a security update to fix a zero-day vulnerability across Cisco Prime Collaboration Deployment.

The addressed vulnerability could allow the unauthenticated remote attacker to perform a cross-site scripting attack on Cisco prime collaboration deployment caused by improper validation of user-supplied input by the web-based management interface.

Cisco Prime Collaboration Deployment Cross-Site Scripting (CVE-2023-20060):

  • CVSS: 6.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Cross-Site Scripting
Vulnerabilities

CVE-2023-20060

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Cisco Security Advisory

References