CVE-2024-20404

HIGH EXPLOITED NUCLEI

Cisco Finesse - Unauthenticated Server-Side Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-20404 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including 3zz4t. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2024-20404, demonstrating an SSRF vulnerability in Cisco Finesse's web-based management interface. It includes a crafted HTTP request to exploit insufficient input validation, allowing unauthenticated remote attackers to probe internal services.

Description

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.

Exploits (2)

nomisec WORKING POC 2 stars
by 3zz4t · poc
https://github.com/3zz4t/CVE-2024-20404

The repository provides a functional proof-of-concept for CVE-2024-20404, demonstrating an SSRF vulnerability in Cisco Finesse's web-based management interface. It includes a crafted HTTP request to exploit insufficient input validation, allowing unauthenticated remote attackers to probe internal services.

Classification
Working Poc 95%
Attack Type
Ssrf
Complexity
Trivial
Reliability
Reliable
Target: Cisco Finesse (web-based management interface)
No auth needed
Prerequisites: Network access to the target system · Cisco Finesse with vulnerable web interface
devstral-2 · analyzed Feb 19, 2026 Full analysis →
vulncheck_xdb WORKING POC
client-side
https://github.com/AbdElRahmanEzzat1995/CVE-2024-20404

The repository provides a functional PoC for CVE-2024-20404, an SSRF vulnerability in Cisco Finesse's web-based management interface. It includes a crafted HTTP request to exploit insufficient input validation, allowing unauthenticated remote attackers to probe internal services.

Classification
Working Poc 95%
Attack Type
Ssrf
Complexity
Trivial
Reliability
Reliable
Target: Cisco Finesse (web-based management interface)
No auth needed
Prerequisites: Network access to the target system
devstral-2 · analyzed Feb 25, 2026 Full analysis →

Nuclei Templates (1)

Cisco Finesse - Server-Side Request Forgery (SSRF)
MEDIUMVERIFIEDby 0x_Akoko
Shodan: title:"Cisco Finesse" port:8445
FOFA: title="Cisco Finesse" && port="8445"

Scores

CVSS v3 7.2
EPSS 0.8113
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2026-02-04
CWE
CWE-918
Status published
Products (3)
cisco/finesse 11.6\(1\) (6 CPE variants)
cisco/finesse 12.6\(2\) (3 CPE variants)
cisco/finesse < 11.6\(1\)
Published Jun 05, 2024
Tracked Since Feb 18, 2026