CVE-2024-20462: Cisco ATA 190 Series Analog Telephone Adapter Muliplatform Firmware Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability is due to incorrect sanitization of HTML content from an affected device. A successful exploit could allow the attacker to view passwords that belong to other users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20462?
CVE-2024-20462 is considered a low severity vulnerability as it impacts local authenticated users with low privileges.
How can I fix CVE-2024-20462?
To remediate CVE-2024-20462, you should upgrade the Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-20462?
CVE-2024-20462 affects users of the Cisco ATA 191 and ATA 192 firmware versions below 12.0.2 and 11.2.5 respectively.
What type of access is required to exploit CVE-2024-20462?
Exploitation of CVE-2024-20462 requires authenticated local access to the affected device.
What is the nature of the vulnerability in CVE-2024-20462?
CVE-2024-20462 is due to incorrect sanitization in the web-based management interface that allows password viewing.