4.7

CVE-2024-20400

A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.

 This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page.

 Note: Cisco Expressway Series refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices.

Data is provided by the National Vulnerability Database (NVD)
CiscoTelepresence Video Communication Server Versionx8.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.1.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.1.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.2.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.2.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.5 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.5.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.5.3 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.6 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.6.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.7 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.7.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.7.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.7.3 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.8 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.8.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.8.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.8.3 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.9 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.9.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.9.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.10.0 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.10.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.10.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.10.3 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.10.4 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.11.0 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.11.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.11.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.11.3 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx8.11.4 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.5.0 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.5.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.5.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.5.3 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.5.4 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.5.5 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.5.6 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.5.7 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.5.8 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.5.9 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.6.0 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.6.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.6.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.6.3 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.6.4 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.7.0 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx12.7.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.3 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.4 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.5 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.6 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.7 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.8 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.9 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.10 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.0.11 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.2.0 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.2.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.2.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.2.5 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.2.6 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.2.7 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.3.0 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.3.1 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.3.2 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.3.3 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.3.4 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx14.3.5 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx15.0.0 SwEditionexpressway
CiscoTelepresence Video Communication Server Versionx15.0.1 SwEditionexpressway
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.89% 0.747
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@cisco.com 4.7 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.