6.5
CVE-2024-20347
- EPSS 0.23%
- Veröffentlicht 03.04.2024 17:15:49
- Zuletzt bearbeitet 11.04.2025 15:47:24
- Erkennungen
A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user, such as deleting users from the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Emergency Responder Version < 12.5(1)su8b
Cisco ≫ Emergency Responder Version 14
Cisco ≫ Emergency Responder Version 14su1
Cisco ≫ Emergency Responder Version 14su2
Cisco ≫ Emergency Responder Version 14su3
Cisco ≫ Emergency Responder Version 14su3a
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.135 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
| Cisco PSIRT | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cem-csrf-suCmNjFr