PT-2024-3800 · Cisco · Cisco Emergency Responder

Tobias Clarke

·

Published

2024-04-03

·

Updated

2024-10-31

·

CVE-2024-20347

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Emergency Responder (affected versions not specified)
Description A vulnerability in the web UI of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack. This is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by persuading a user to click a crafted link, allowing the attacker to perform arbitrary actions with the privilege level of the affected user, such as deleting users from the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

BDU:2024-04174
CVE-2024-20347

Affected Products

Cisco Emergency Responder