Unauthenticated Remote Attacker Couldview or Delete Configuration or Change Firmware on Affected Devices
CVE-2024-20458
8.2HIGH
What is CVE-2024-20458?
A significant vulnerability exists in the web-based management interface of Cisco's ATA 190 Series Analog Telephone Adapter. The flaw enables an unauthenticated remote attacker to interact with specific HTTP endpoints that lack adequate authentication controls. By exploiting this vulnerability, a malicious actor could navigate to particular URLs, leading to potential viewing or deletion of device configurations. Additionally, the exploit could allow the attacker to alter the device's firmware, posing a serious risk to users and network security. Organizations utilizing affected devices are urged to assess their security posture and implement necessary measures to mitigate risks associated with this vulnerability.