VYPR
Unrated severityNVD Advisory· Published Jun 20, 2022· Updated Aug 3, 2024

CVE-2022-31734

CVE-2022-31734

Description

Reflected XSS in error page generation on Cisco Catalyst 2940 Series Switches (firmware prior to 12.2(50)SY) allows arbitrary script execution in user's browser.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in error page generation on Cisco Catalyst 2940 Series Switches (firmware prior to 12.2(50)SY) allows arbitrary script execution in user's browser.

Vulnerability

Cisco Catalyst 2940 Series Switches with firmware versions prior to 12.2(50)SY contain a reflected cross-site scripting (XSS) vulnerability in error page generation. The product improperly processes user input when generating error messages, leading to CWE-79 [1].

Exploitation

An attacker can craft a malicious URL containing JavaScript and convince an authenticated user with network access to the switch's web interface to click the link. The crafted input is reflected in the error page, executing the script in the user's browser. No authentication is required for the attacker, but user interaction is necessary [1].

Impact

Successful exploitation allows the attacker to execute arbitrary script in the victim's browser, potentially leading to information disclosure or session hijacking. The CVSS v3 score is 4.6 (Medium) with vector CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N [1].

Mitigation

Cisco Catalyst 2940 Series Switches have been end-of-support since January 2015, and no firmware updates will be released. Users are strongly advised to stop using the affected products and migrate to alternative supported switches [1][2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.