CVE-2024-20369: Cisco Network Services Orchestrator

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.

Affected products

  • Cisco Network Services Orchestrator: from 5.4, before 5.5.10.1 (fixed in 5.5.10.1); from 5.6, before 5.6.14.3 (fixed in 5.6.14.3); from 5.7, before 5.7.15 (fixed in 5.7.15); from 5.8, before 5.8.13.1 (fixed in 5.8.13.1); from 6.0, before 6.0.12 (fixed in 6.0.12); from 6.1, before 6.1.7 (fixed in 6.1.7); …

Published 2024-05-15. Last modified 2026-06-17.