CVE-2024-20404 is a Server-Side Request Forgery (SSRF) vulnerability in the web-based management interface of Cisco Finesse, stemming from insufficient input validation. An unauthenticated, remote attacker can exploit this by sending a crafted HTTP request, potentially allowing them to obtain limited sensitive information from services associated with the affected device. Rated as Medium severity (CVSS 5.3), it has a low attack complexity and does not require user interaction or privileges. While there is no evidence of active exploitation, Metasploit modules, or ExploitDB entries, a Nuclei template for this vulnerability exists, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.6\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:finesse:*:*:*:*:*:*:*:* | ||
11.6\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:finesse:11.6\(1\):-:*:*:*:*:*:* | ||
11.6\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:finesse:11.6\(1\):es4:*:*:*:*:*:* | ||
11.6\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:finesse:11.6\(1\):es5:*:*:*:*:*:* | ||
11.6\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:finesse:11.6\(1\):es6:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.