CVE-2024-20404
published 2024-06-05CVE-2024-20404: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected…
PriorityP180medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
21.74%
97.4th percentile
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system.
This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_finesse | — | — |
| cisco | cisco_finesse | — | — |
| cisco | cisco_finesse | — | — |
| cisco | cisco_packaged_contact_center_enterprise | — | — |
| cisco | cisco_unified_contact_center_enterprise | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | finesse | < 11.6\(1\) | 11.6\(1\) |
| cisco | finesse | — | — |
| cisco | finesse | — | — |
| cisco | finesse_web-based | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlPOST /gadgets/metadata HTTP/1.1
path/gadgets/metadata
port8445
- →SSRF exploit targets POST /gadgets/metadata endpoint with a crafted JSON body containing an attacker-controlled URL in the 'gadgets[].url' field; look for outbound HTTP requests originating from the Finesse server to external/internal hosts triggered by this endpoint.
- →Fingerprint exposed Cisco Finesse instances via Shodan/FOFA using title 'Cisco Finesse' on port 8445 to identify attack surface.
- ·The SSRF vulnerability requires no authentication; any unauthenticated remote attacker can send the crafted POST request directly to the /gadgets/metadata endpoint. ↗
- ·There are no workarounds available for this vulnerability; only vendor-supplied software updates remediate it. ↗
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vulncheck7.2HIGH
vendor_cisco7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Finesse Web-Based Management Interface Vulnerabilities
vendor_cisco·2024-06-05·CVSS 7.2
CVE-2024-20404 [HIGH] CWE-20 Cisco Finesse Web-Based Management Interface Vulnerabilities
Cisco Finesse Web-Based Management Interface Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to perform a stored cross site-scripting (XSS) attack by exploiting a remote file inclusion (RFI) vulnerability or perform a server-side request forgery (SSRF) attack an affected system.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-rfi-Um7wT8Ew
Cisco
Cisco Finesse Web-Based Management Interface Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2024-20404 Cisco Finesse Web-Based Management Interface Vulnerabilities
CVE-2024-20404: Cisco Finesse Web-Based Management Interface Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to perform a stored cross site-scripting (XSS) attack by exploiting a remote file inclusion (RFI) vulnerability or perform a server-side request forgery (SSRF) attack an affected system. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-20, CWE-918, CWE-20, CWE-918
Bug IDs: CSCwh95276, CSCwh95292, CSCwk36966, CSCwh95292, CSCwk36966
GHSA
GHSA-vhv4-j9cm-5cjx: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an
ghsa_unreviewed·2024-06-05
CVE-2024-20404 [HIGH] CWE-918 GHSA-vhv4-j9cm-5cjx: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system.
This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.
VulnCheck
Cisco finesse Server-Side Request Forgery (SSRF)
vulncheck·2024·CVSS 7.2
CVE-2024-20404 [HIGH] Cisco finesse Server-Side Request Forgery (SSRF)
Cisco finesse Server-Side Request Forgery (SSRF)
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system.
This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.
Affected: Cisco finesse
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation
No detection rules found.
Nuclei
Cisco Finesse - Server-Side Request Forgery (SSRF)
nuclei·CVSS 5.3
CVE-2024-20404 [MEDIUM] Cisco Finesse - Server-Side Request Forgery (SSRF)
Cisco Finesse - Server-Side Request Forgery (SSRF)
Cisco Finesse contains an SSRF caused by insufficient validation of user-supplied input in HTTP requests, letting unauthenticated remote attackers access limited sensitive information, exploit requires sending crafted HTTP requests.
Template:
id: CVE-2024-20404
info:
name: Cisco Finesse - Server-Side Request Forgery (SSRF)
author: 0x_Akoko
severity: medium
description: |
Cisco Finesse contains an SSRF caused by insufficient validation of user-supplied input in HTTP requests, letting unauthenticated remote attackers access limited sensitive information, exploit requires sending crafted HTTP requests.
impact: |
Attackers can access sensitive information from services associated with the device, potentially leading to information disclosu
No writeups or analysis indexed.
2024-06-05
Published
Exploited in the wild