Directory Traversal Vulnerability in Cisco Emergency Responder
CVE-2024-20352

4.9MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
3 April 2024

Badges

👾 Exploit Exists

Summary

A vulnerability in Cisco Emergency Responder enables an authenticated, remote attacker to execute a directory traversal attack. This attack arises from inadequate protections in the web user interface of the affected system. By sending specially crafted requests to the web UI, an attacker can exploit this vulnerability to perform arbitrary actions with the affected user's privileges. Such actions may include accessing sensitive information like password or log files, and managing files by uploading or deleting them from the system.

Affected Version(s)

Cisco Emergency Responder 10.5(1a)

Cisco Emergency Responder 10.5(1)

Cisco Emergency Responder 11.5(4)SU2

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

.