CVE-2024-20429
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-20429 is a vulnerability affecting the web-based management interface of Cisco AsyncOS for Secure Email Gateway. This issue allows authenticated, remote attackers to execute arbitrary system commands on the device due to insufficient input validation in certain areas of the interface. An attacker could exploit this flaw by crafting and sending malicious HTTP requests to the affected device. If successful, the attacker could gain root privileges and execute commands on the underlying operating system. To take advantage of this vulnerability, the attacker requires valid Operator credentials.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Secure Email
Affected Vendors
- Cisco Systems Inc