PT-2024-9830 · Cisco · Cisco Unified Communications Manager+1

Lukasz Plonka

·

Published

2024-08-11

·

Updated

2024-09-06

·

CVE-2024-20488

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Unified Communications Manager versions prior to the fixed version Cisco Unified Communications Manager Session Management Edition versions prior to the fixed version
Description: The issue is related to a lack of input validation in the web-based management interface, which could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This could be achieved by persuading a user to click a crafted link, potentially allowing the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
Recommendations: For Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition, upgrade to a version that includes the fix for this issue as soon as possible to mitigate the threat. As a temporary workaround, consider restricting access to the web-based management interface to minimize the risk of exploitation. Avoid using the interface to click on links from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-11608
CVE-2024-20488

Affected Products

Cisco Unified Communications Manager
Cisco Unified Communications Manager Session Management Edition