CVE Database
/

CVE-2024-20414

Back to search

CVE-2024-20414

Published: Sep 25, 2024

Modified: Sep 25, 2024

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI. This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could exploit this vulnerability by persuading a currently authenticated administrator to follow a crafted link. A successful exploit could allow the attacker to change the configuration of the affected device.

VendorProductVersions

Cisco

IOS

affected
15.2(6)E2
affected
15.2(7)E
affected
15.2(6)E2a
affected
15.2(6)E2b
affected
15.2(7)E1

+25 more versions

Cisco

Cisco IOS XE Software

affected
3.2.0SG
affected
3.2.1SG
affected
3.2.2SG
affected
3.2.3SG
affected
3.2.4SG

+426 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

None

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now