Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20404

Опубликовано: 05 июн. 2024
Источник: nvd
CVSS3: 7.2
CVSS3: 5.3
EPSS Высокий

Описание

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system.

This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:finesse:*:*:*:*:*:*:*:*
Версия до 11.6\(1\) (исключая)
cpe:2.3:a:cisco:finesse:11.6\(1\):-:*:*:*:*:*:*
cpe:2.3:a:cisco:finesse:11.6\(1\):es4:*:*:*:*:*:*
cpe:2.3:a:cisco:finesse:11.6\(1\):es5:*:*:*:*:*:*
cpe:2.3:a:cisco:finesse:11.6\(1\):es6:*:*:*:*:*:*
cpe:2.3:a:cisco:finesse:11.6\(1\):es7:*:*:*:*:*:*
cpe:2.3:a:cisco:finesse:11.6\(1\):es8:*:*:*:*:*:*
cpe:2.3:a:cisco:finesse:12.6\(2\):-:*:*:*:*:*:*
cpe:2.3:a:cisco:finesse:12.6\(2\):es01:*:*:*:*:*:*
cpe:2.3:a:cisco:finesse:12.6\(2\):es02:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.75952
Высокий

7.2 High

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-918
CWE-918

Связанные уязвимости

CVSS3: 7.2
github
больше 1 года назад

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.

CVSS3: 7.2
fstec
больше 1 года назад

Уязвимость веб-интерфейса управления программного средства автоматизации работы операторов Cisco Finesse, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 99%
0.75952
Высокий

7.2 High

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-918
CWE-918