CVE-2024-20492

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 77

Summary

CVE-2024-20492 is a vulnerability affecting the restricted shell of Cisco Expressway Series devices. An authenticated, local attacker with Administrator-level credentials and read-write privileges can exploit this issue through command injection, allowing them to escape the restricted shell and gain root privileges on the underlying operating system. This vulnerability arises from insufficient validation of user-supplied input, enabling attackers to submit crafted CLI commands for exploitation. Affected devices include Cisco Expressway Control (Expressway-C) and Cisco Expressway Edge (Expressway-E).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Telepresence Video Communication Server

Affected Vendors

  • Cisco