CVE-2024-20352 is a directory traversal vulnerability in Cisco Emergency Responder, affecting its web UI. An authenticated, remote attacker can exploit this by sending crafted requests, leading to arbitrary actions on the device. With a CVSS score of 8.8 (HIGH), successful exploitation allows attackers to access sensitive files, upload/delete data, and perform other actions with the affected user's privileges. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.5(1)su8bCPE matchmatch criteria | cpe:2.3:a:cisco:emergency_responder:*:*:*:*:*:*:*:* | ||
14CPE matchmatch criteria | cpe:2.3:a:cisco:emergency_responder:14:*:*:*:*:*:*:* | ||
14su1CPE matchmatch criteria | cpe:2.3:a:cisco:emergency_responder:14su1:*:*:*:*:*:*:* | ||
14su2CPE matchmatch criteria | cpe:2.3:a:cisco:emergency_responder:14su2:*:*:*:*:*:*:* | ||
14su3CPE matchmatch criteria | cpe:2.3:a:cisco:emergency_responder:14su3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.