CVE-2024-20400
MEDIUM EPSS 29.6%
Published Jul 17, 20241y ago · Modified Jun 17, 20261w ago
4.7 CVSS 3.1
Published Jul 17, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
Description
A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page. Note: Cisco Expressway Series refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality None
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
29.6% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-601
Affected Products 74
| Vendor | Product | Version | Range |
|---|---|---|---|
| cisco | telepresence_video_communication_server | x8.1 | any |
| cisco | telepresence_video_communication_server | x8.1.1 | any |
| cisco | telepresence_video_communication_server | x8.1.2 | any |
| cisco | telepresence_video_communication_server | x8.2 | any |
| cisco | telepresence_video_communication_server | x8.2.1 | any |
| cisco | telepresence_video_communication_server | x8.2.2 | any |
| cisco | telepresence_video_communication_server | x8.5 | any |
| cisco | telepresence_video_communication_server | x8.5.1 | any |
| cisco | telepresence_video_communication_server | x8.5.3 | any |
| cisco | telepresence_video_communication_server | x8.6 | any |
| cisco | telepresence_video_communication_server | x8.6.1 | any |
| cisco | telepresence_video_communication_server | x8.7 | any |
| cisco | telepresence_video_communication_server | x8.7.1 | any |
| cisco | telepresence_video_communication_server | x8.7.2 | any |
| cisco | telepresence_video_communication_server | x8.7.3 | any |
| cisco | telepresence_video_communication_server | x8.8 | any |
| cisco | telepresence_video_communication_server | x8.8.1 | any |
| cisco | telepresence_video_communication_server | x8.8.2 | any |
| cisco | telepresence_video_communication_server | x8.8.3 | any |
| cisco | telepresence_video_communication_server | x8.9 | any |
| cisco | telepresence_video_communication_server | x8.9.1 | any |
| cisco | telepresence_video_communication_server | x8.9.2 | any |
| cisco | telepresence_video_communication_server | x8.10.0 | any |
| cisco | telepresence_video_communication_server | x8.10.1 | any |
| cisco | telepresence_video_communication_server | x8.10.2 | any |
| cisco | telepresence_video_communication_server | x8.10.3 | any |
| cisco | telepresence_video_communication_server | x8.10.4 | any |
| cisco | telepresence_video_communication_server | x8.11.0 | any |
| cisco | telepresence_video_communication_server | x8.11.1 | any |
| cisco | telepresence_video_communication_server | x8.11.2 | any |
| cisco | telepresence_video_communication_server | x8.11.3 | any |
| cisco | telepresence_video_communication_server | x8.11.4 | any |
| cisco | telepresence_video_communication_server | x12.5.0 | any |
| cisco | telepresence_video_communication_server | x12.5.1 | any |
| cisco | telepresence_video_communication_server | x12.5.2 | any |
| cisco | telepresence_video_communication_server | x12.5.3 | any |
| cisco | telepresence_video_communication_server | x12.5.4 | any |
| cisco | telepresence_video_communication_server | x12.5.5 | any |
| cisco | telepresence_video_communication_server | x12.5.6 | any |
| cisco | telepresence_video_communication_server | x12.5.7 | any |
| cisco | telepresence_video_communication_server | x12.5.8 | any |
| cisco | telepresence_video_communication_server | x12.5.9 | any |
| cisco | telepresence_video_communication_server | x12.6.0 | any |
| cisco | telepresence_video_communication_server | x12.6.1 | any |
| cisco | telepresence_video_communication_server | x12.6.2 | any |
| cisco | telepresence_video_communication_server | x12.6.3 | any |
| cisco | telepresence_video_communication_server | x12.6.4 | any |
| cisco | telepresence_video_communication_server | x12.7.0 | any |
| cisco | telepresence_video_communication_server | x12.7.1 | any |
| cisco | telepresence_video_communication_server | x14.0.1 | any |
| cisco | telepresence_video_communication_server | x14.0.2 | any |
| cisco | telepresence_video_communication_server | x14.0.3 | any |
| cisco | telepresence_video_communication_server | x14.0.4 | any |
| cisco | telepresence_video_communication_server | x14.0.5 | any |
| cisco | telepresence_video_communication_server | x14.0.6 | any |
| cisco | telepresence_video_communication_server | x14.0.7 | any |
| cisco | telepresence_video_communication_server | x14.0.8 | any |
| cisco | telepresence_video_communication_server | x14.0.9 | any |
| cisco | telepresence_video_communication_server | x14.0.10 | any |
| cisco | telepresence_video_communication_server | x14.0.11 | any |
| cisco | telepresence_video_communication_server | x14.2.0 | any |
| cisco | telepresence_video_communication_server | x14.2.1 | any |
| cisco | telepresence_video_communication_server | x14.2.2 | any |
| cisco | telepresence_video_communication_server | x14.2.5 | any |
| cisco | telepresence_video_communication_server | x14.2.6 | any |
| cisco | telepresence_video_communication_server | x14.2.7 | any |
| cisco | telepresence_video_communication_server | x14.3.0 | any |
| cisco | telepresence_video_communication_server | x14.3.1 | any |
| cisco | telepresence_video_communication_server | x14.3.2 | any |
| cisco | telepresence_video_communication_server | x14.3.3 | any |
| cisco | telepresence_video_communication_server | x14.3.4 | any |
| cisco | telepresence_video_communication_server | x14.3.5 | any |
| cisco | telepresence_video_communication_server | x15.0.0 | any |
| cisco | telepresence_video_communication_server | x15.0.1 | any |
References 1
- sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-redirect-KJsFuXgj
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.