SB20260819137 - Multiple vulnerabilities in Cisco Industrial Ethernet 1000 Series Switches



SB20260819137 - Multiple vulnerabilities in Cisco Industrial Ethernet 1000 Series Switches

Published: August 19, 2026

Security Bulletin ID SB20260819137
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) (CVE-ID: CVE-2026-20232)

CWE-ID: CWE-80 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary script code in the context of another user.

The vulnerability exists due to insufficient validation of user-supplied input in the web-based management interface when processing user-supplied input in specific pages of the interface. A remote user can inject malicious code into specific pages of the interface to execute arbitrary script code in the context of another user.

User interaction is required for another user of the interface to load the injected content.


2) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-20177)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to insufficient protection against management plane flooding attacks in management plane packet handling when processing a high rate of ICMP, SSH, or HTTP traffic. A remote attacker can send a high rate of ICMP, SSH, or HTTP traffic to cause a denial of service.

Successful exploitation causes the device manager web GUI, SSH, or API to become inaccessible, while data traffic through the device is not affected.


Remediation

Install update from vendor's website.