Directory Traversal Vulnerability in Cisco Emergency Responder
CVE-2024-20352
4.9MEDIUM
Summary
A vulnerability in Cisco Emergency Responder enables an authenticated, remote attacker to execute a directory traversal attack. This attack arises from inadequate protections in the web user interface of the affected system. By sending specially crafted requests to the web UI, an attacker can exploit this vulnerability to perform arbitrary actions with the affected user's privileges. Such actions may include accessing sensitive information like password or log files, and managing files by uploading or deleting them from the system.
Affected Version(s)
Cisco Emergency Responder 10.5(1a)
Cisco Emergency Responder 10.5(1)
Cisco Emergency Responder 11.5(4)SU2
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published