CVE-2024-20347
published 2024-04-03CVE-2024-20347: A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to…
PriorityP337medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.23%
13.9th percentile
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user, such as deleting users from the device.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_emergency_responder | — | — |
| cisco | emergency_responder | < 12.5(1)su8b | 12.5(1)su8b |
| cisco | emergency_responder | — | — |
| cisco | emergency_responder | — | — |
| cisco | emergency_responder | — | — |
| cisco | emergency_responder | — | — |
| cisco | emergency_responder | — | — |
| cisco | emergency_responder | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
vendor_cisco4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2vqq-3rpw-85f7: A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker
ghsa_unreviewed·2024-04-03
CVE-2024-20347 [MEDIUM] CWE-352 GHSA-2vqq-3rpw-85f7: A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user, such as deleting users from the device.
Cisco
Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
vendor_cisco·2024-04-03·CVSS 4.9
CVE-2024-20347 [MEDIUM] CWE-23 Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
Multiple vulnerabilities in Cisco Emergency Responder could allow an attacker to conduct a cross-site request forgery (CSRF) or directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cem-csrf-suCmNjFr
Cisco
Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2024-20347 Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
CVE-2024-20347: Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
Multiple vulnerabilities in Cisco Emergency Responder could allow an attacker to conduct a cross-site request forgery (CSRF) or directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-23, CWE-352, CWE-23, CWE-352
Bug IDs: CSCwf41263, CSCwf41347, CSCwf41263, CSCwf41347
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-03
Published