cbcvebase.
CVE-2024-20404
published 2024-06-05

CVE-2024-20404: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected…

PriorityP180medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
21.74%
97.4th percentile
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.

Affected

10 ranges
VendorProductVersion rangeFixed in
ciscocisco_finesse
ciscocisco_finesse
ciscocisco_finesse
ciscocisco_packaged_contact_center_enterprise
ciscocisco_unified_contact_center_enterprise
ciscocisco_unified_contact_center_express
ciscofinesse< 11.6\(1\)11.6\(1\)
ciscofinesse
ciscofinesse
ciscofinesse_web-based

Detection & IOCsextracted from sources · hover to see the quote

urlPOST /gadgets/metadata HTTP/1.1
path/gadgets/metadata
port8445
  • SSRF exploit targets POST /gadgets/metadata endpoint with a crafted JSON body containing an attacker-controlled URL in the 'gadgets[].url' field; look for outbound HTTP requests originating from the Finesse server to external/internal hosts triggered by this endpoint.
  • Fingerprint exposed Cisco Finesse instances via Shodan/FOFA using title 'Cisco Finesse' on port 8445 to identify attack surface.
  • ·The SSRF vulnerability requires no authentication; any unauthenticated remote attacker can send the crafted POST request directly to the /gadgets/metadata endpoint.
  • ·There are no workarounds available for this vulnerability; only vendor-supplied software updates remediate it.

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vulncheck7.2HIGH
vendor_cisco7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.