Cisco disclosed today a zero-day vulnerability in the company's Prime Collaboration Deployment (PCD) software that can be exploited for cross-site scripting attacks.

This server management utility allows administrators to perform migration or upgrade tasks on servers in their organization's inventory.
The CVE-2023-20060 flaw was discovered in the web-based management interface of Cisco PCD 14 and earlier by Pierre Vivegnis of the NATO (NCSC).
Successful exploitation allows unauthenticated attackers to launch remote cross-site scripting attacks, but requires user interaction.
“This vulnerability exists because the web-based management interface does not properly validate user- provided input . An attacker could exploit this vulnerability by convincing a user of the interface to click on a crafted link ,” Cisco explains.
“A successful exploit could allow an attacker to execute arbitrary script code within the affected interface or gain access to sensitive browser-.”
While Cisco shared information regarding the impact of the flaw, the company will release security updates to address it sometime next month. For now, there are no available solutions to mitigate the attack vector.
Fortunately, Cisco's Product Security Incident Response Team (PSIRT) has not yet found evidence of malicious use by hackers and is not aware of public exploit code targeting the bug.

The zero-day was disclosed in December still awaiting a patch
Cisco must also fix another high-severity IP Phone zero-day (CVE-2022-20968) with publicly available exploit code, which was disclosed in early December 2023.
Cisco's PSIRT warned then that “it knows that the proof-of-concept exploit code is available” and that “the vulnerability has been discussed publicly”.
While the company promised that security updates would be released in January 2023, the bug remains unpatched months after the initial disclosure.
The devices affected by CVE-2022-20968 include Cisco IP phones with firmware version 7800 and 8800 Series 14.2 and earlier.
Although Cisco did not provide a solution for this IP Phone zero-day, it advised administrators to implement temporary mitigation measures, which require disabling Cisco Discovery Protocol on affected devices that support Link Layer Discovery Protocol (LLDP) as an alternative.
Information source: bleepingcomputer.com
