CVE-2024-20414: CSRF
A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI. This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could exploit this vulnerability by persuading a currently authenticated administrator to follow a crafted link. A successful exploit could allow the attacker to change the configuration of the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20414?
The severity of CVE-2024-20414 is classified as high due to its potential for cross-site request forgery (CSRF) exploitation.
How do I fix CVE-2024-20414?
To fix CVE-2024-20414, it's recommended to upgrade to a patched version of the affected Cisco IOS or Cisco IOS XE software.
What systems are affected by CVE-2024-20414?
CVE-2024-20414 affects multiple versions of Cisco IOS and IOS XE, including 3.2.0se to 3.13.x and various versions of IOS XE from 16.1.1 up to 17.12.3.
What type of attack can CVE-2024-20414 facilitate?
CVE-2024-20414 can facilitate a cross-site request forgery (CSRF) attack, allowing an unauthenticated remote attacker to manipulate the affected system.
Is user authentication required to exploit CVE-2024-20414?
No, user authentication is not required to exploit CVE-2024-20414, which increases its potential risk.