Directory Traversal Vulnerability in Cisco Emergency Responder
CVE-2024-20352
8.8HIGH
What is CVE-2024-20352?
A vulnerability in Cisco Emergency Responder enables an authenticated, remote attacker to execute a directory traversal attack. This attack arises from inadequate protections in the web user interface of the affected system. By sending specially crafted requests to the web UI, an attacker can exploit this vulnerability to perform arbitrary actions with the affected user's privileges. Such actions may include accessing sensitive information like password or log files, and managing files by uploading or deleting them from the system.
Affected Version(s)
Cisco Emergency Responder 10.5(1a)
Cisco Emergency Responder 10.5(1)
Cisco Emergency Responder 11.5(4)SU2