CVE-2024-20352
published 2024-04-03CVE-2024-20352: A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the…
PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.47%
71.0th percentile
A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by sending crafted requests to the web UI. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user, such as accessing password or log files or uploading and deleting existing files from the system.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Directory traversal attack via crafted requests to the Cisco Emergency Responder web UI — monitor for path traversal sequences (e.g., '../') in HTTP requests targeting the CER web interface ↗
- →Successful exploitation may result in access to password or log files, or upload/deletion of files — alert on unexpected file access or modification events on Cisco Emergency Responder systems ↗
- →CVE-2024-20352 is tracked under Cisco Bug IDs CSCwf41263 and CSCwf41347 — use these IDs to correlate vendor advisories and patch status in asset management/SIEM ↗
- ·Exploitation requires an authenticated session — the attacker must already have valid credentials to the Cisco Emergency Responder web UI, limiting unauthenticated attack surface ↗
- ·No workarounds are available — patching via Cisco software updates is the only remediation path ↗
- ·The advisory covers two distinct vulnerability classes (CSRF and Directory Traversal) under the same advisory — ensure detection coverage addresses both CWE-352 (CSRF) and CWE-23 (Path Traversal) ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
vendor_cisco·2024-04-03·CVSS 4.9
CVE-2024-20347 [MEDIUM] CWE-23 Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
Multiple vulnerabilities in Cisco Emergency Responder could allow an attacker to conduct a cross-site request forgery (CSRF) or directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cem-csrf-suCmNjFr
Cisco
Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2024-20352 Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
CVE-2024-20352: Cisco Emergency Responder Cross-Site Request Forgery and Directory Traversal Vulnerabilities
Multiple vulnerabilities in Cisco Emergency Responder could allow an attacker to conduct a cross-site request forgery (CSRF) or directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-23, CWE-352, CWE-23, CWE-352
Bug IDs: CSCwf41263, CSCwf41347, CSCwf41263, CSCwf41347
GHSA
GHSA-4pgp-hx9q-53rp: A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow
ghsa_unreviewed·2024-04-03
CVE-2024-20352 [MEDIUM] CWE-22 GHSA-4pgp-hx9q-53rp: A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow
A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by sending crafted requests to the web UI. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user, such as accessing password or log files or uploading and deleting existing files from the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-03
Published