CVE-2024-20369: Input Validation
A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20369?
CVE-2024-20369 has a severity rating of Medium due to its potential to allow unauthenticated remote attackers to redirect users.
How do I fix CVE-2024-20369?
To fix CVE-2024-20369, update to the latest version of Cisco Crosswork Network Services Orchestrator as advised by Cisco.
What impact does CVE-2024-20369 have on network security?
CVE-2024-20369 can lead to phishing attacks by redirecting users to malicious web pages, compromising network security.
Who is affected by CVE-2024-20369?
CVE-2024-20369 affects all users of Cisco Crosswork Network Services Orchestrator who use the web-based management interface.
Is authentication required to exploit CVE-2024-20369?
No, CVE-2024-20369 can be exploited by unauthenticated users, making it particularly concerning for network security.