Unauthenticated Remote Attacker Couldview or Delete Configuration or Change Firmware on Affected Devices
CVE-2024-20458
8.2HIGH
Summary
A significant vulnerability exists in the web-based management interface of Cisco's ATA 190 Series Analog Telephone Adapter. The flaw enables an unauthenticated remote attacker to interact with specific HTTP endpoints that lack adequate authentication controls. By exploiting this vulnerability, a malicious actor could navigate to particular URLs, leading to potential viewing or deletion of device configurations. Additionally, the exploit could allow the attacker to alter the device's firmware, posing a serious risk to users and network security. Organizations utilizing affected devices are urged to assess their security posture and implement necessary measures to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published