CVE-2024-20462
MEDIUMCisco ATA 190 Series - Info Disclosure
Title source: llmDescription
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability is due to incorrect sanitization of HTML content from an affected device. A successful exploit could allow the attacker to view passwords that belong to other users.
Scores
CVSS v3
5.5
EPSS
0.0012
EPSS Percentile
31.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
CWE-257
CWE-922
Status
published
Affected Products (2)
cisco/ata_191_firmware
< 12.0.2
cisco/ata_192_firmware
< 11.2.5
Timeline
Published
Oct 16, 2024
Tracked Since
Feb 18, 2026