Directory Traversal Vulnerability in Cisco Emergency Responder
CVE-2024-20352

8.8HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
3 April 2024

Badges

👾 Exploit Exists

What is CVE-2024-20352?

A vulnerability in Cisco Emergency Responder enables an authenticated, remote attacker to execute a directory traversal attack. This attack arises from inadequate protections in the web user interface of the affected system. By sending specially crafted requests to the web UI, an attacker can exploit this vulnerability to perform arbitrary actions with the affected user's privileges. Such actions may include accessing sensitive information like password or log files, and managing files by uploading or deleting them from the system.

Affected Version(s)

Cisco Emergency Responder 10.5(1a)

Cisco Emergency Responder 10.5(1)

Cisco Emergency Responder 11.5(4)SU2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

.
CVE-2024-20352 : Directory Traversal Vulnerability in Cisco Emergency Responder