CVE-2024-20400

MEDIUM

Cisco Expressway Series - Open Redirect

Title source: llm
STIX 2.1

Description

A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page. Note: Cisco Expressway Series refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices.

Scores

CVSS v3 4.7
EPSS 0.0038
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (50)
cisco/telepresence_video_communication_server x8.1
cisco/telepresence_video_communication_server x8.1.1
cisco/telepresence_video_communication_server x8.1.2
cisco/telepresence_video_communication_server x8.2
cisco/telepresence_video_communication_server x8.2.1
cisco/telepresence_video_communication_server x8.2.2
cisco/telepresence_video_communication_server x8.5
cisco/telepresence_video_communication_server x8.5.1
cisco/telepresence_video_communication_server x8.5.3
cisco/telepresence_video_communication_server x8.6
... and 40 more
Published Jul 17, 2024
Tracked Since Feb 18, 2026