6.4
CVE-2024-20475
- EPSS 0.11%
- Published 25.09.2024 17:15:17
- Last modified 03.10.2024 17:49:17
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious data into a specific data field in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Catalyst Sd-wan Manager Version20.6.0.18.3
Cisco ≫ Catalyst Sd-wan Manager Version20.6.0.18.4
Cisco ≫ Catalyst Sd-wan Manager Version20.6.1
Cisco ≫ Catalyst Sd-wan Manager Version20.6.1.0.1
Cisco ≫ Catalyst Sd-wan Manager Version20.6.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.6.1.2
Cisco ≫ Catalyst Sd-wan Manager Version20.6.2
Cisco ≫ Catalyst Sd-wan Manager Version20.6.2.0.4
Cisco ≫ Catalyst Sd-wan Manager Version20.6.2.1
Cisco ≫ Catalyst Sd-wan Manager Version20.6.2.2
Cisco ≫ Catalyst Sd-wan Manager Version20.6.2.2.2
Cisco ≫ Catalyst Sd-wan Manager Version20.6.2.2.3
Cisco ≫ Catalyst Sd-wan Manager Version20.6.2.2.4
Cisco ≫ Catalyst Sd-wan Manager Version20.6.2.2.7
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.2
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.5
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.7
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.10
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.11
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.14
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.18
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.19
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.23
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.25
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.27
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.29
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.33
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.39
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.40
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.47
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.0.51
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.2
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.3
Cisco ≫ Catalyst Sd-wan Manager Version20.6.3.4
Cisco ≫ Catalyst Sd-wan Manager Version20.6.4.0.19
Cisco ≫ Catalyst Sd-wan Manager Version20.6.4.1
Cisco ≫ Catalyst Sd-wan Manager Version20.6.5.1
Cisco ≫ Catalyst Sd-wan Manager Version20.6.5.1.5
Cisco ≫ Catalyst Sd-wan Manager Version20.6.5.1.7
Cisco ≫ Catalyst Sd-wan Manager Version20.6.5.1.10
Cisco ≫ Catalyst Sd-wan Manager Version20.6.5.1.11
Cisco ≫ Catalyst Sd-wan Manager Version20.6.5.1.14
Cisco ≫ Catalyst Sd-wan Manager Version20.6.5.2
Cisco ≫ Catalyst Sd-wan Manager Version20.6.5.2.3
Cisco ≫ Catalyst Sd-wan Manager Version20.6.5.2.4
Cisco ≫ Catalyst Sd-wan Manager Version20.6.5.4
Cisco ≫ Catalyst Sd-wan Manager Version20.6.6.0.1
Cisco ≫ Catalyst Sd-wan Manager Version20.6.7
Cisco ≫ Catalyst Sd-wan Manager Version20.7.1
Cisco ≫ Catalyst Sd-wan Manager Version20.7.1.0.2
Cisco ≫ Catalyst Sd-wan Manager Version20.7.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.7.1eft2
Cisco ≫ Catalyst Sd-wan Manager Version20.7.2
Cisco ≫ Catalyst Sd-wan Manager Version20.8.1
Cisco ≫ Catalyst Sd-wan Manager Version20.9.1_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.9.2.2
Cisco ≫ Catalyst Sd-wan Manager Version20.9.2.3
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3.0.3
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3.0.4
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3.0.12
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3.0.18
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3.0.21
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3.0.23
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3.0.24
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3.0.25
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3.0.26
Cisco ≫ Catalyst Sd-wan Manager Version20.9.3_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.9.4
Cisco ≫ Catalyst Sd-wan Manager Version20.9.4.0.4
Cisco ≫ Catalyst Sd-wan Manager Version20.9.4.1
Cisco ≫ Catalyst Sd-wan Manager Version20.9.4.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.9.4.1.3
Cisco ≫ Catalyst Sd-wan Manager Version20.9.4.1_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.9.4_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.9.5
Cisco ≫ Catalyst Sd-wan Manager Version20.9.5.1
Cisco ≫ Catalyst Sd-wan Manager Version20.9.5.1_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.9.5.2_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.9.5_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.10.1
Cisco ≫ Catalyst Sd-wan Manager Version20.10.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.10.1.2
Cisco ≫ Catalyst Sd-wan Manager Version20.10.1_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.11.1
Cisco ≫ Catalyst Sd-wan Manager Version20.11.1.1
Cisco ≫ Catalyst Sd-wan Manager Version20.11.1.2
Cisco ≫ Catalyst Sd-wan Manager Version20.11.1_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.12.1
Cisco ≫ Catalyst Sd-wan Manager Version20.12.1_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.12.2
Cisco ≫ Catalyst Sd-wan Manager Version20.12.2_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.12.3
Cisco ≫ Catalyst Sd-wan Manager Version20.12.3.1
Cisco ≫ Catalyst Sd-wan Manager Version20.12.3_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.12.4
Cisco ≫ Catalyst Sd-wan Manager Version20.13.1
Cisco ≫ Catalyst Sd-wan Manager Version20.13.1_li_images
Cisco ≫ Catalyst Sd-wan Manager Version20.14.1
Cisco ≫ Catalyst Sd-wan Manager Version20.14.1_li_images
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.297 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
psirt@cisco.com | 6.4 | 3.1 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.