CVE-2024-20421

A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cisco:ata_191_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ata_191:-:*:*:*:on-premises:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:cisco:ata_191_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ata_191:-:*:*:*:multiplatform:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:cisco:ata_192_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ata_192:-:*:*:*:multiplatform:*:*:*

History

No history.

Information

Published : 2024-10-16 17:15

Updated : 2024-10-31 14:35


NVD link : CVE-2024-20421

Mitre link : CVE-2024-20421

CVE.ORG link : CVE-2024-20421


JSON object : View

Products Affected

cisco

  • ata_192
  • ata_192_firmware
  • ata_191_firmware
  • ata_191
CWE
CWE-352

Cross-Site Request Forgery (CSRF)