CSRF Vulnerability in Cisco Emergency Responder Affects Company Operations
CVE-2024-20347
6.5MEDIUM
What is CVE-2024-20347?
A vulnerability in Cisco Emergency Responder could allow unauthorized remote attackers to execute a Cross-Site Request Forgery (CSRF) attack. This flaw stems from inadequate protection measures in the web interface of the system. By enticing a user to click on a specially crafted link, an attacker could leverage this vulnerability to perform arbitrary actions with the privileges of the user, which may include critical operations like deleting users on the device. Ensuring robust security practices and implementing safeguards against CSRF is essential for protecting affected systems.
Affected Version(s)
Cisco Emergency Responder