Rewterz
Rewterz Threat Alert – Multiple GitLab Community Edition and Enterprise Edition Vulnerabilities
January 29, 2024
Rewterz
Rewterz Threat Update –Medusa Ransomware Claims Attack on Kansas City Area Transportation Authority
January 29, 2024

Rewterz Threat Alert – CVE-2024-20305 – Cisco Unity Connection Vulnerability

Severity

Medium

Analysis Summary

CVE-2024-20305

Cisco Unity Connection is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the web-based management interface. A remote authenticated attacker could exploit this vulnerability using a specially crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials

Impact

  • Cross-Site Scripting

Indicators Of Compromise

CVE

  • CVE-2024-20305

Affected Vendors

Cisco

Affected Products

  • Cisco Unity Connection 11.0
  • Cisco Unity Connection 14
  • Cisco Unity Connection 11.5 (1)

Remediation

Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information.

Cisco Security Advisory