CVE-2024-20404
Cisco finesse Server-Side Request Forgery (SSRF)
Record summary
CVE-2024-20404 has a selected CVSS score of 7.2 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.
Exploitation context
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
Cisco FinesseBrowse Cisco / Cisco Finesse | CVE List | 12.6(2) | affected |
| 12.6(2)ES1 | affected | ||
| 12.6(2)ES2 | affected | ||
Cisco Packaged Contact Center EnterpriseBrowse Cisco / Cisco Packaged Contact Center Enterprise | CVE List | Version range not supplied | affected |
Cisco Unified Contact Center EnterpriseBrowse Cisco / Cisco Unified Contact Center Enterprise | CVE List | Version range not supplied | affected |
Cisco Unified Contact Center ExpressBrowse Cisco / Cisco Unified Contact Center Express | CVE List | Version range not supplied | affected |
finesseBrowse Cisco / finesse | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHub3zz4t/CVE-2024-20404Repository PoCby 3zz4tStars: 2Not analyzed4 files
Nuclei templates
1ProjectDiscoveryMEDIUMCisco Finesse - Server-Side Request Forgery (SSRF)CVSS 5.8
Cisco Finesse contains an SSRF caused by insufficient validation of user-supplied input in HTTP requests, letting unauthenticated remote attackers access limited sensitive information, exploit requires sending crafted HTTP requests.
Impact
Attackers can access sensitive information from services associated with the device, potentially leading to information disclosure.
Remediation
Apply the latest security patches and updates provided by Cisco for Finesse.
Source: ProjectDiscovery