CVE-2024-20458 is a high-severity vulnerability affecting the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapters (models 191 and 192). This flaw stems from a lack of authentication on specific HTTP endpoints, allowing an unauthenticated, remote attacker to view or delete device configurations or alter firmware. The vulnerability has a CVSS score of 8.2 (High) due to its network-based attack vector, low attack complexity, and high impact on integrity and low impact on availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.0.2CPE matchmatch criteria | cpe:2.3:o:cisco:ata_191_firmware:*:*:*:*:*:*:*:* | ||
< 11.2.5CPE matchmatch criteria | cpe:2.3:o:cisco:ata_191_firmware:*:*:*:*:*:*:*:* | ||
< 11.2.5CPE matchmatch criteria | cpe:2.3:o:cisco:ata_192_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.