CSRF Vulnerability in Cisco Emergency Responder Affects Company Operations
CVE-2024-20347

4.3MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
3 April 2024

Badges

👾 Exploit Exists

Summary

A vulnerability in Cisco Emergency Responder could allow unauthorized remote attackers to execute a Cross-Site Request Forgery (CSRF) attack. This flaw stems from inadequate protection measures in the web interface of the system. By enticing a user to click on a specially crafted link, an attacker could leverage this vulnerability to perform arbitrary actions with the privileges of the user, which may include critical operations like deleting users on the device. Ensuring robust security practices and implementing safeguards against CSRF is essential for protecting affected systems.

Affected Version(s)

Cisco Emergency Responder

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

.