CVE-2024-20352: Path Traversal
A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by sending crafted requests to the web UI. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user, such as accessing password or log files or uploading and deleting existing files from the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20352?
The severity of CVE-2024-20352 is classified as medium due to its potential for directory traversal attacks.
How do I fix CVE-2024-20352?
To fix CVE-2024-20352, update your Cisco Emergency Responder to the latest version provided by Cisco that addresses this vulnerability.
What type of attack is associated with CVE-2024-20352?
CVE-2024-20352 is associated with a directory traversal attack that allows an authenticated remote attacker to perform arbitrary actions on the device.
Who is affected by CVE-2024-20352?
CVE-2024-20352 affects users of Cisco Emergency Responder who have not implemented the necessary security updates.
What are the potential consequences of CVE-2024-20352?
The potential consequences of CVE-2024-20352 include unauthorized access to sensitive files and the ability to execute arbitrary commands on the affected device.