CVE-2024-20497Improper Authorization in Cisco Expressway-e

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 57.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4

Description

A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is due to inadequate authorization checks for Mobile and Remote Access (MRA) users. An attacker could exploit this vulnerability by running a series of crafted commands. A successful exploit could allow the attacker to intercept calls that are destined for a particular phone number or to make phone calls and have that phone

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Cisco Expressway Edge Improper Authorization Vulnerability2024-09-04
GHSA
GHSA-2vgj-5cmq-q6q3: A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected sys2024-09-04

📋Vendor Advisories

1
Cisco
Cisco Expressway Edge Improper Authorization Vulnerability2024-09-04
CVE-2024-20497 — Improper Authorization in Cisco | cvebase