CVE-2024-20405: Cisco Finesse

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.

Affected products

  • Cisco Finesse: before 11.6\(1\) (fixed in 11.6\(1\)); version 11.6(1) only; version 12.6(2) only

Published 2024-06-05. Last modified 2026-06-17.