CVE-2025-20317
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious webpage and potentially capture user credentials. Note: The affected vKVM client is also included in Cisco UCS Manager.
Published:Aug 27, 2025
Last Modified:Apr 15, 2026
EPS:Aug 27, 2025
EPSS Score:0.00033
CVSS Score:7.1
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Integrated Management Controller
Cisco
Integrated Management Controller
Vendor
Cisco
Product
Ucs Manager
Cisco
Ucs Manager
Vendor
Cisco
Product
Virtual Keyboard Video Monitor
Cisco
Virtual Keyboard Video Monitor
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
