CVE-2024-20492
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Summary
CVE-2024-20492 is a vulnerability affecting the restricted shell of Cisco Expressway Series devices. An authenticated, local attacker with Administrator-level credentials and read-write privileges can exploit this issue through command injection, allowing them to escape the restricted shell and gain root privileges on the underlying operating system. This vulnerability arises from insufficient validation of user-supplied input, enabling attackers to submit crafted CLI commands for exploitation. Affected devices include Cisco Expressway Control (Expressway-C) and Cisco Expressway Edge (Expressway-E).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Telepresence Video Communication Server
Affected Vendors
- Cisco