A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user, such as deleting users from the device.
History

Thu, 31 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-04-03T16:27:10.856Z

Updated: 2024-10-31T13:40:17.857Z

Reserved: 2023-11-08T15:08:07.646Z

Link: CVE-2024-20347

cve-icon Vulnrichment

Updated: 2024-08-01T21:59:41.536Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-03T17:15:49.107

Modified: 2024-10-31T14:35:05.260

Link: CVE-2024-20347

cve-icon Redhat

No data.