CVE-2024-20404: Cisco Finesse
Medium severity, CVSS 5.3. EPSS: 22.6% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on an affected system. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated to the affected device.
Affected products
- Cisco Finesse: before 11.6\(1\) (fixed in 11.6\(1\)); version 11.6(1) only; version 12.6(2) only
Published 2024-06-05. Last modified 2026-06-17.