Cisco NSO Vulnerability: Unauthenticated Remote Redirection to Malicious Website
CVE-2024-20369
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 15 May 2024
What is CVE-2024-20369?
A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Network Services Orchestrator 5.4
Cisco Network Services Orchestrator 5.5
Cisco Network Services Orchestrator 5.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved