CVE-2024-20345 is a directory traversal vulnerability in the file upload functionality of Cisco AppDynamics Controller. This flaw, caused by insufficient input validation, allows an authenticated, remote attacker to access sensitive data on affected devices. With a CVSS score of 6.5 (Medium), it requires low privileges and network access, but has a high impact on confidentiality. While there is no known active exploitation, public exploit code, or KEV entry, the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 23.4.0CPE matchmatch criteria | cpe:2.3:a:cisco:appdynamics_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.