A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user, such as deleting users from the device.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2024-04-03T16:27:10.856Z
Updated: 2024-10-31T13:40:17.857Z
Reserved: 2023-11-08T15:08:07.646Z
Link: CVE-2024-20347
Vulnrichment
Updated: 2024-08-01T21:59:41.536Z
NVD
Status : Awaiting Analysis
Published: 2024-04-03T17:15:49.107
Modified: 2024-10-31T14:35:05.260
Link: CVE-2024-20347
Redhat
No data.