Cisco Integrated Management Controller Virtual Keyboard Video Monitor Open Redirect Vulnerability
TL;DR π
- A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading a user to click a craftedβ¦
- Highest CVSS: 7.1 (High).
- Check the advisory for fixed releases β remediation detail is in the vendor link below.
- CVEs: CVE-2025-20317.
What it is
CVE-2025-20317 is an open redirect vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC). The vKVM client is also embedded in Cisco UCS Manager, so both are affected.
The flaw stems from insufficient verification of vKVM endpoints. An unauthenticated, remote attacker doesn’t need any credentials on the target system, but does need the victim to click a crafted link. Once that happens, the user’s session is redirected to an attacker-controlled webpage. Cisco notes this could be used to capture user credentials, presumably via a page that mimics the legitimate IMC/UCS Manager login flow.
This sits on the management plane β it affects the interface administrators use to reach server hardware consoles, not the data plane. CVSS 3.1 base score is 7.1 (HIGH), vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N: network-reachable, low attack complexity, no privileges required, but user interaction is required, with high confidentiality impact and low integrity impact.
The affected component is present across a wide range of hardware: Catalyst 8300 Series Edge uCPE, UCS Manager Software, UCS B-Series Blade Servers, UCS C-Series M6/M7/M8 Rack Servers, UCS E-Series Servers M6, and UCS X-Series Modular System. It also extends to any Cisco appliance built on a preconfigured UCS C-Series server that exposes the Cisco IMC UI β this list includes APIC servers, Business Edition 6000/7000, Catalyst Center (formerly DNA Center), Telemetry Broker, CSP 5000, CSPC, CMX, Cyber Vision Center, Expressway, HyperFlex Edge/Nodes, IEC6400, IOS XRv 9000, Meeting Server 1000, Nexus Dashboard, Prime Infrastructure, Prime Network Registrar Jumpstart, Secure Endpoint Private Cloud, Secure Firewall Management Center, Secure Malware Analytics, Secure Network Analytics, Secure Network Server, and Secure Workload appliances. UCS C-Series M5, UCS E-Series M3, UCS S-Series Storage Servers, and 5000 Series ENCS are confirmed not affected.
What to do
- Treat this as applicable to any IMC or UCS Manager instance, and to any of the listed appliances that expose the Cisco IMC UI, regardless of current configuration.
- There are no workarounds β patching is the only remediation path. Cisco has published fixed firmware/software per product line; check the advisory’s fixed software table for your exact platform and version.
- Some appliances have distinct update mechanisms worth noting directly: IEC6400 Edge Compute Appliances need the HUU image IEC6400-HUU-4.3.5.img; Secure Firewall Management Center Appliances need Hotfix l on top of 4.3(6.250053); Secure Malware Analytics Appliances require the Out-of-Band Firmware Update ISO; Secure Network Analytics Appliances need patch-common-SNA-FIRMWARE-20250403-v2-01.swu; Secure Network Server Appliances need the BIOS/HUU upgrade documented for the SNS 3700 firmware 4.x line. Confirm the correct package for your specific appliance model before applying.
- Since exploitation depends on a user clicking a crafted link, brief IMC/UCS Manager administrators to be cautious with unsolicited links to management interfaces, particularly ones that could resemble legitimate vKVM session URLs β this doesn’t replace patching but reduces exposure while updates are scheduled.
- After patching, verify the running firmware/software version against the fixed release listed for your specific product in the advisory, since the mapping between hardware line and fixed version differs by platform.
For leadership π§
Executive summary. Administrators who manage Cisco UCS hardware and a long list of Cisco appliances built on it could be tricked into handing over their management-interface credentials via a crafted link, with no authentication needed by the attacker. There’s no workaround, so this needs to move into the patch queue now rather than waiting for a routine cycle.
Why it matters:
- The vulnerable vKVM endpoint sits in Cisco IMC and UCS Manager, the interfaces admins use to reach server hardware consoles, so a successful redirect can expose credentials with high confidentiality impact.
- No authentication is required by the attacker, only a single click from a legitimate administrator on a crafted link, making this a phishing-style entry point into management infrastructure rather than a network intrusion.
- The affected component is embedded across a very wide hardware base – UCS B/C/E/X-Series, Catalyst 8300 uCPE – and inherited by dozens of downstream appliances (APIC, Firewall Management Center, HyperFlex, Nexus Dashboard, Secure Network Analytics, and more) whenever they expose the IMC UI.
- There is no workaround; the only mitigation is applying the version-specific firmware or software fix, several of which require distinct update mechanisms (HUU images, hotfixes, out-of-band ISOs) rather than a standard upgrade path.
Now / Next / Later:
- Now: Identify every Cisco IMC and UCS Manager instance, plus any of the listed appliances exposing the IMC UI, and warn administrators against clicking unsolicited links to those management interfaces until patched.
- Next: Apply the fixed firmware or software for each specific platform in your next change window, using the correct mechanism per appliance (e.g. the IEC6400 HUU image, the Secure Firewall Management Center hotfix, the Secure Malware Analytics OOB ISO, or the Secure Network Analytics SWU patch).
- Later: Build a recurring inventory check that maps every UCS-derived appliance in your estate to its Cisco IMC/UCS Manager firmware version, so future advisories affecting this shared component can be triaged and patched without a fresh discovery exercise each time.