#VU98784 Authentication Bypass by Primary Weakness in Cisco Systems, Inc products - CVE-2024-20463
Published: October 17, 2024
Vulnerability identifier: #VU98784
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-20463
CWE-ID: CWE-305
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
ATA 191 Multiplatform Analog Telephone Adapter
ATA 192 Multiplatform Analog Telephone Adapter
ATA 190 Series Analog Telephone Adapters
ATA 191 Multiplatform Analog Telephone Adapter
ATA 192 Multiplatform Analog Telephone Adapter
ATA 190 Series Analog Telephone Adapters
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the HTTP server allowing state changes in GET requests. A remote attacker can make limited modifications to the configuration or reboot the device, leading to a denial of service (DoS) condition.
Remediation
Install updates from vendor's website.