Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-20325


A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access control implementations on cluster configuration CLI requests. An attacker could exploit this vulnerability by sending a cluster configuration CLI request to specific directories on an affected device. A successful exploit could allow the attacker to read and modify data that is handled by an internal service on the affected device.


Published

2024-02-21T17:15:09.180

Last Modified

2025-05-06T17:43:06.773

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco unified_intelligence_center < 12.5(1)_es03 Yes
Application cisco unified_intelligence_center < 12.6(1)_es08 Yes
Application cisco unified_intelligence_center < 12.6(2)ES02 Yes

References