Cisco Catalyst Center Cross-Site Scripting Vulnerability

๐ŸšจSEVERITY: MEDIUM โ€” CVSS 6.1Security Advisory

TL;DR ๐Ÿ“Œ

  • A vulnerability in the web-based management interface of Cisco Catalyst Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user ofโ€ฆ
  • Highest CVSS: 6.1 (Medium).
  • Fix available โ€” see the first fixed release below.
  • CVEs: CVE-2025-20353.

What it is

CVE-2025-20353 is a cross-site scripting flaw in the web-based management interface of Cisco Catalyst Center. It results from insufficient validation of user input in that interface.

The attack path requires no authentication and works over the network, but it does need user interaction: an attacker persuades a user of the Catalyst Center management interface to click a crafted link. There’s no indication of a way to trigger this without that click.

A successful exploit lets the attacker execute arbitrary script code in the context of the management interface, or access sensitive browser-based information โ€” session data, tokens, or anything else the browser holds for that origin. This is a management-plane issue affecting users of the web UI, not a data-plane compromise of network traffic.

Cisco Catalyst Center Virtual Appliance is confirmed not affected. The physical/standard appliance is affected regardless of configuration.

What to do

  • Upgrade Catalyst Center releases 2.3.7 and earlier to the fixed release 2.3.7.10.
  • Release 3.1 is not affected, so no action is needed there beyond confirming your running version.
  • There are no workarounds โ€” Cisco states this explicitly, so mitigation means upgrading, not configuration changes.
  • Since exploitation relies on a user clicking a crafted link, remind Catalyst Center administrators and operators to be cautious with unsolicited links pointing at the management interface until upgraded.
  • Confirm whether you’re running the physical/standard appliance (affected) versus the Virtual Appliance (confirmed not vulnerable) to scope your remediation correctly.

Fixed releases

Affected release First fixed release
2.3.7.10 3.1

For leadership ๐Ÿงญ

Executive summary. Cisco Catalyst Center’s management console can be tricked into running attacker-supplied script if an operator clicks a crafted link, potentially exposing session tokens for that interface. There’s no workaround, so this should be scheduled into the next upgrade cycle rather than left open.

Why it matters:

  • The flaw sits in the web-based management interface used by network administrators to configure and monitor Catalyst Center, not in data-plane traffic handling.
  • Exploitation needs no authentication, only a click on a crafted link, making phishing-style delivery to Catalyst Center operators a realistic path.
  • A successful attack can pull session data or tokens from the operator’s browser, potentially giving an attacker a foothold into the management session itself.
  • Only the physical/standard appliance is affected; the Virtual Appliance has been confirmed not vulnerable, so scoping by deployment type matters.

Now / Next / Later:

  • Now: placeholder
  • Next: placeholder
  • Later: placeholder

Source