PT-2024-9830 · Cisco · Cisco Unified Communications Manager+1
Lukasz Plonka
·
Published
2024-08-11
·
Updated
2024-09-06
·
CVE-2024-20488
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Unified Communications Manager versions prior to the fixed version
Cisco Unified Communications Manager Session Management Edition versions prior to the fixed version
Description:
The issue is related to a lack of input validation in the web-based management interface, which could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This could be achieved by persuading a user to click a crafted link, potentially allowing the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
Recommendations:
For Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition, upgrade to a version that includes the fix for this issue as soon as possible to mitigate the threat.
As a temporary workaround, consider restricting access to the web-based management interface to minimize the risk of exploitation.
Avoid using the interface to click on links from untrusted sources until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Unified Communications Manager
Cisco Unified Communications Manager Session Management Edition