CVE-2024-20437
25.09.2024, 17:15
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack and execute commands on the CLI of an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an already authenticated user to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.
Vendor | Product | Version |
---|---|---|
cisco | ios_xe | 17.3.2 |
cisco | ios_xe | 17.3.2a:a |
cisco | ios_xe | 17.3.3 |
cisco | ios_xe | 17.3.4 |
cisco | ios_xe | 17.3.4a:a |
cisco | ios_xe | 17.3.4b:b |
cisco | ios_xe | 17.3.4c:c |
cisco | ios_xe | 17.3.5 |
cisco | ios_xe | 17.3.5a:a |
cisco | ios_xe | 17.3.5b:b |
cisco | ios_xe | 17.3.6 |
cisco | ios_xe | 17.3.7 |
cisco | ios_xe | 17.3.8 |
cisco | ios_xe | 17.3.8a:a |
cisco | ios_xe | 17.4.1 |
cisco | ios_xe | 17.4.1a:a |
cisco | ios_xe | 17.4.1b:b |
cisco | ios_xe | 17.4.2 |
cisco | ios_xe | 17.4.2a:a |
cisco | ios_xe | 17.5.1 |
cisco | ios_xe | 17.5.1a:a |
cisco | ios_xe | 17.6.1 |
cisco | ios_xe | 17.6.1a:a |
cisco | ios_xe | 17.6.1w:w |
cisco | ios_xe | 17.6.1x:x |
cisco | ios_xe | 17.6.1y:y |
cisco | ios_xe | 17.6.1z:z |
cisco | ios_xe | 17.6.1z1:z1 |
cisco | ios_xe | 17.6.2 |
cisco | ios_xe | 17.6.3 |
cisco | ios_xe | 17.6.3a:a |
cisco | ios_xe | 17.6.4 |
cisco | ios_xe | 17.6.5 |
cisco | ios_xe | 17.6.5a:a |
cisco | ios_xe | 17.6.6 |
cisco | ios_xe | 17.6.6a:a |
cisco | ios_xe | 17.7.1 |
cisco | ios_xe | 17.7.1a:a |
cisco | ios_xe | 17.7.1b:b |
cisco | ios_xe | 17.7.2 |
cisco | ios_xe | 17.8.1 |
cisco | ios_xe | 17.8.1a:a |
cisco | ios_xe | 17.9.1 |
cisco | ios_xe | 17.9.1a:a |
cisco | ios_xe | 17.9.1w:w |
cisco | ios_xe | 17.9.1x:x |
cisco | ios_xe | 17.9.1x1:x1 |
cisco | ios_xe | 17.9.1y:y |
cisco | ios_xe | 17.9.1y1:y1 |
cisco | ios_xe | 17.9.2 |
cisco | ios_xe | 17.9.2a:a |
cisco | ios_xe | 17.9.3 |
cisco | ios_xe | 17.9.3a:a |
cisco | ios_xe | 17.9.4 |
cisco | ios_xe | 17.9.4a:a |
cisco | ios_xe | 17.10.1 |
cisco | ios_xe | 17.10.1a:a |
cisco | ios_xe | 17.10.1b:b |
cisco | ios_xe | 17.11.1 |
cisco | ios_xe | 17.11.1a:a |
cisco | ios_xe | 17.11.99sw:sw |
cisco | ios_xe | 17.12.1 |
cisco | ios_xe | 17.12.1a:a |
cisco | ios_xe | 17.12.1w:w |
cisco | ios_xe | 17.12.1x:x |
cisco | ios_xe | 17.12.1y:y |
𝑥
= Vulnerable software versions
Common Weakness Enumeration