CVE-2024-20405
published 2024-06-05CVE-2024-20405: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by…
PriorityP432medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.65%
46.8th percentile
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability.
This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_finesse | — | — |
| cisco | cisco_finesse | — | — |
| cisco | cisco_finesse | — | — |
| cisco | cisco_packaged_contact_center_enterprise | — | — |
| cisco | cisco_unified_contact_center_enterprise | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | finesse | < 11.6\(1\) | 11.6\(1\) |
| cisco | finesse | — | — |
| cisco | finesse | — | — |
| cisco | finesse_web-based | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Finesse Web-Based Management Interface Vulnerabilities
vendor_cisco·2024-06-05·CVSS 7.2
CVE-2024-20404 [HIGH] CWE-20 Cisco Finesse Web-Based Management Interface Vulnerabilities
Cisco Finesse Web-Based Management Interface Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to perform a stored cross site-scripting (XSS) attack by exploiting a remote file inclusion (RFI) vulnerability or perform a server-side request forgery (SSRF) attack an affected system.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-rfi-Um7wT8Ew
Cisco
Cisco Finesse Web-Based Management Interface Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2024-20405 Cisco Finesse Web-Based Management Interface Vulnerabilities
CVE-2024-20405: Cisco Finesse Web-Based Management Interface Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to perform a stored cross site-scripting (XSS) attack by exploiting a remote file inclusion (RFI) vulnerability or perform a server-side request forgery (SSRF) attack an affected system. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-20, CWE-918, CWE-20, CWE-918
Bug IDs: CSCwh95276, CSCwh95292, CSCwk36966, CSCwh95292, CSCwk36966
GHSA
GHSA-gg5f-6jp8-fpqw: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack
ghsa_unreviewed·2024-06-05
CVE-2024-20405 [MEDIUM] CWE-20 GHSA-gg5f-6jp8-fpqw: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability.
This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-05
Published