CVE-2024-20488: Cisco Unified Communications Manager Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20488?
The severity of CVE-2024-20488 is critical due to the potential for unauthenticated remote attackers to exploit it.
How do I fix CVE-2024-20488?
To fix CVE-2024-20488, users should apply the latest patch or upgrade to a secured version of the Cisco Unified Communications Manager.
Which Cisco Unified Communications Manager versions are affected by CVE-2024-20488?
CVE-2024-20488 affects several versions, including 12.5(1), 12.6(1), 14.0, and 15.0 among others.
What type of vulnerability is CVE-2024-20488?
CVE-2024-20488 is a cross-site scripting (XSS) vulnerability found in the web-based management interface of Cisco Unified Communications Manager.
Can CVE-2024-20488 be exploited remotely?
Yes, CVE-2024-20488 can be exploited remotely by an unauthenticated attacker.