8.8

CVE-2024-20437

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack and execute commands on the CLI of an affected device.

 This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an already authenticated user to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Xe Version 17.3.2
Cisco ≫ Ios Xe Version 17.3.2a
Cisco ≫ Ios Xe Version 17.3.3
Cisco ≫ Ios Xe Version 17.3.4
Cisco ≫ Ios Xe Version 17.3.4a
Cisco ≫ Ios Xe Version 17.3.4b
Cisco ≫ Ios Xe Version 17.3.4c
Cisco ≫ Ios Xe Version 17.3.5
Cisco ≫ Ios Xe Version 17.3.5a
Cisco ≫ Ios Xe Version 17.3.5b
Cisco ≫ Ios Xe Version 17.3.6
Cisco ≫ Ios Xe Version 17.3.7
Cisco ≫ Ios Xe Version 17.3.8
Cisco ≫ Ios Xe Version 17.3.8a
Cisco ≫ Ios Xe Version 17.4.1
Cisco ≫ Ios Xe Version 17.4.1a
Cisco ≫ Ios Xe Version 17.4.1b
Cisco ≫ Ios Xe Version 17.4.2
Cisco ≫ Ios Xe Version 17.4.2a
Cisco ≫ Ios Xe Version 17.5.1
Cisco ≫ Ios Xe Version 17.5.1a
Cisco ≫ Ios Xe Version 17.6.1
Cisco ≫ Ios Xe Version 17.6.1a
Cisco ≫ Ios Xe Version 17.6.1w
Cisco ≫ Ios Xe Version 17.6.1x
Cisco ≫ Ios Xe Version 17.6.1y
Cisco ≫ Ios Xe Version 17.6.1z
Cisco ≫ Ios Xe Version 17.6.1z1
Cisco ≫ Ios Xe Version 17.6.2
Cisco ≫ Ios Xe Version 17.6.3
Cisco ≫ Ios Xe Version 17.6.3a
Cisco ≫ Ios Xe Version 17.6.4
Cisco ≫ Ios Xe Version 17.6.5
Cisco ≫ Ios Xe Version 17.6.5a
Cisco ≫ Ios Xe Version 17.6.6
Cisco ≫ Ios Xe Version 17.6.6a
Cisco ≫ Ios Xe Version 17.7.1
Cisco ≫ Ios Xe Version 17.7.1a
Cisco ≫ Ios Xe Version 17.7.1b
Cisco ≫ Ios Xe Version 17.7.2
Cisco ≫ Ios Xe Version 17.8.1
Cisco ≫ Ios Xe Version 17.8.1a
Cisco ≫ Ios Xe Version 17.9.1
Cisco ≫ Ios Xe Version 17.9.1a
Cisco ≫ Ios Xe Version 17.9.1w
Cisco ≫ Ios Xe Version 17.9.1x
Cisco ≫ Ios Xe Version 17.9.1x1
Cisco ≫ Ios Xe Version 17.9.1y
Cisco ≫ Ios Xe Version 17.9.1y1
Cisco ≫ Ios Xe Version 17.9.2
Cisco ≫ Ios Xe Version 17.9.2a
Cisco ≫ Ios Xe Version 17.9.3
Cisco ≫ Ios Xe Version 17.9.3a
Cisco ≫ Ios Xe Version 17.9.4
Cisco ≫ Ios Xe Version 17.9.4a
Cisco ≫ Ios Xe Version 17.10.1
Cisco ≫ Ios Xe Version 17.10.1a
Cisco ≫ Ios Xe Version 17.10.1b
Cisco ≫ Ios Xe Version 17.11.1
Cisco ≫ Ios Xe Version 17.11.1a
Cisco ≫ Ios Xe Version 17.11.99sw
Cisco ≫ Ios Xe Version 17.12.1
Cisco ≫ Ios Xe Version 17.12.1a
Cisco ≫ Ios Xe Version 17.12.1w
Cisco ≫ Ios Xe Version 17.12.1x
Cisco ≫ Ios Xe Version 17.12.1y
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.229
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Cisco PSIRT 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-csrf-ycUYxkKO
Vendor Advisory