CVE-2025-20317
published 2025-08-27CVE-2025-20317: A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an…
PriorityP340high7.1CVSS 3.1
AVNACLPRNUIRSUCHILAN
EPSS
0.46%
37.2th percentile
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website.
This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious webpage and potentially capture user credentials.
Note: The affected vKVM client is also included in Cisco UCS Manager.
Affected
294 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
| cisco | cisco_unified_computing_system | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q9qm-m8mx-29xg: A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauth
ghsa_unreviewed·2025-08-27
CVE-2025-20317 [HIGH] CWE-601 GHSA-q9qm-m8mx-29xg: A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauth
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website.
This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious webpage and potentially capture user credentials.
Note: The affected vKVM client is also included in Cisco UCS Manager.
Cisco
Cisco Integrated Management Controller Virtual Keyboard Video Monitor Open Redirect Vulnerability
vendor_cisco·2025-08-27·CVSS 7.1
CVE-2025-20317 [HIGH] CWE-601 Cisco Integrated Management Controller Virtual Keyboard Video Monitor Open Redirect Vulnerability
Cisco Integrated Management Controller Virtual Keyboard Video Monitor Open Redirect Vulnerability
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website.
This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious webpage and potentially capture user credentials.
Note: The affected vKVM client is also included in Cisco UCS Manager.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vu
Cisco
Cisco Integrated Management Controller Virtual Keyboard Video Monitor Open Redirect Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20317 Cisco Integrated Management Controller Virtual Keyboard Video Monitor Open Redirect Vulnerability
CVE-2025-20317: Cisco Integrated Management Controller Virtual Keyboard Video Monitor Open Redirect Vulnerability
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious webpage and potentially capture user credentials. Note: The affected vKVM client is also included in Cisco UCS Manager. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-27
Published