Record summary

CVE-2024-20405 has a selected CVSS score of 4.8 (medium); EIP currently links 1 repository PoC.

Description

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 7, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
CVE List12.6(2)affected
12.6(2)ES1affected
12.6(2)ES2affected

Cisco Packaged Contact Center Enterprise

Browse Cisco / Cisco Packaged Contact Center Enterprise
CVE ListVersion range not suppliedaffected

Cisco Unified Contact Center Enterprise

Browse Cisco / Cisco Unified Contact Center Enterprise
CVE ListVersion range not suppliedaffected

Cisco Unified Contact Center Express

Browse Cisco / Cisco Unified Contact Center Express
CVE ListVersion range not suppliedaffected

Proofs of concept

1

Repository PoCs

GitHub3zz4t/CVE-2024-20405Repository PoCby 3zz4tStars: 1Not analyzed7 files

1.2 MiB

GitHub

PoC details

References

2