CVE-2024-20429

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jul 17, 2024
Updated: Jul 18, 2024
CWE ID 74

Summary

CVE-2024-20429 is a vulnerability affecting the web-based management interface of Cisco AsyncOS for Secure Email Gateway. This issue allows authenticated, remote attackers to execute arbitrary system commands on the device due to insufficient input validation in certain areas of the interface. An attacker could exploit this flaw by crafting and sending malicious HTTP requests to the affected device. If successful, the attacker could gain root privileges and execute commands on the underlying operating system. To take advantage of this vulnerability, the attacker requires valid Operator credentials.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Secure Email

Affected Vendors

  • Cisco Systems Inc