CVE-2024-20346 - CVE House
Back to Database
Status published Medium CVE-2024-20346

A vulnerability in the web-based management interface of Cisco AppDynamics...

Vulnerability Description

A vulnerability in the web-based management interface of Cisco AppDynamics Controller could allow an authenticated, remote attacker to perform a reflected cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-20346

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco AppDynamics
Vulnerable Versions:
21.2.0, 21.2.1, 21.2.2, 21.2.3, 21.2.6, 21.2.7, 21.2.8, 21.4.0, 21.4.10, 21.4.11, 21.4.2, 21.4.3, 21.4.4, 21.4.5, 21.4.6, 21.4.7, 21.4.8, 21.4.9, 21.11.0, 21.5.0, 21.6.0, 21.12.0, 21.12.2, 21.12.1, 22.1.0, 22.1.1, 22.11.0, 22.3.0, 22.10.0, 22.12.0, 22.12.1, 21.7.0, 22.8.0, 23.2.0, 23.4.0, 23.7.1, 23.7.0

Timeline

Official Publish: March 6th, 2024
Last Modified: August 1st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)