First published: Wed Aug 21 2024(Updated: )
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =12.5\(1\) | |
Cisco Unified Communications Manager | =12.5\(1\)su1 | |
Cisco Unified Communications Manager | =12.5\(1\)su2 | |
Cisco Unified Communications Manager | =12.5\(1\)su3 | |
Cisco Unified Communications Manager | =12.5\(1\)su4 | |
Cisco Unified Communications Manager | =12.5\(1\)su5 | |
Cisco Unified Communications Manager | =12.5\(1\)su6 | |
Cisco Unified Communications Manager | =12.5\(1\)su7 | |
Cisco Unified Communications Manager | =12.5\(1\)su7a | |
Cisco Unified Communications Manager | =12.5\(1\)su8 | |
Cisco Unified Communications Manager | =12.5\(1\)su8a | |
Cisco Unified Communications Manager | =12.5\(1\)su9 | |
Cisco Unified Communications Manager | =12.6\(1\) | |
Cisco Unified Communications Manager | =14.0 | |
Cisco Unified Communications Manager | =14.0su1 | |
Cisco Unified Communications Manager | =14.0su2 | |
Cisco Unified Communications Manager | =14.0su2a | |
Cisco Unified Communications Manager | =14.0su3 | |
Cisco Unified Communications Manager | =14.0su4 | |
Cisco Unified Communications Manager | =14.0su4a | |
Cisco Unified Communications Manager | =15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-20488 is critical due to the potential for unauthenticated remote attackers to exploit it.
To fix CVE-2024-20488, users should apply the latest patch or upgrade to a secured version of the Cisco Unified Communications Manager.
CVE-2024-20488 affects several versions, including 12.5(1), 12.6(1), 14.0, and 15.0 among others.
CVE-2024-20488 is a cross-site scripting (XSS) vulnerability found in the web-based management interface of Cisco Unified Communications Manager.
Yes, CVE-2024-20488 can be exploited remotely by an unauthenticated attacker.