A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user, such as deleting users from the device.
History

Fri, 11 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco emergency Responder
CPEs cpe:2.3:a:cisco:emergency_responder:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:emergency_responder:14:*:*:*:*:*:*:*
cpe:2.3:a:cisco:emergency_responder:14su1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:emergency_responder:14su2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:emergency_responder:14su3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:emergency_responder:14su3a:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco emergency Responder

Thu, 31 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-10-31T13:40:17.857Z

Reserved: 2023-11-08T15:08:07.646Z

Link: CVE-2024-20347

cve-icon Vulnrichment

Updated: 2024-08-01T21:59:41.536Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-03T17:15:49.107

Modified: 2025-04-11T15:47:24.267

Link: CVE-2024-20347

cve-icon Redhat

No data.