CVE-2024-20460
Cisco ATA 190 Series Analog Telephone Adapter Firmware Reflected Cross-Site Scripting Vulnerability
Description
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information on an affected device.
Weakness: CWE-80
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Analog Telephone Adaptor | Other Products | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Analog Telephone Adaptor (ATA) Software
Vendor advisory
cisco-sa-ata19x-multi-RDTEqRsy
Cisco ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilities
Cisco’s rating: High (advisory CVSS 8.2) · Published Oct 16, 2024 · updated Oct 24, 2024 (revision 1.1)
Bug IDs: CSCwf28037 , CSCwf28041 , CSCwf28048 , CSCwf28097 , CSCwf28102 , CSCwf28188 , CSCwf28191 , CSCwf28345 , CSCwf28348 , CSCwf28378 , CSCwf28398 , CSCwf28421 , CSCwf28426 , CSCwf28499 , CSCwf30963
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from