Executive brief
Cisco Industrial Ethernet 1000 Series Switches include a web-based management interface used to configure and monitor industrial network equipment. An authenticated attacker with valid user credentials can inject malicious scripts into the interface that execute in the context of other users, potentially allowing them to steal session data, modify device settings, or impersonate legitimate administrators.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the web-based management interface caused by insufficient validation of user-supplied input. An authenticated attacker can inject malicious JavaScript code into specific pages of the interface; the payload is stored and executed when other users access the affected pages. The attack requires valid user credentials and user interaction (another user must visit the compromised page). A successful exploit allows arbitrary script execution in the context of another user's session. Patches are available: IE 1000 Series running release 1.9 should upgrade to 1.9.6 or later.
Affected products
- Cisco IE 1000 Series Switches Earlier than 1.9.6
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed in IE 1000 Series release 1.9.6