MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2024-20507

CVSS 4.3v3.1pub. 2024-11-06upd. 2025-07-23

A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to improper storage of sensitive information within the web-based management interface of an affected device. An attacker could exploit this vulnerability by logging in to the web-based management interface. A successful exploit could allow the attacker to view sensitive data that is stored on the affected device.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • Cisco Meeting Management

    APP
    Cisco
    < 3.10.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-20156CRITICAL9.9PL ✓same product

Privilege escalation w REST API Cisco Meeting Management do poziomu administratora

CVE-2026-20098HIGH8.8same product

A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated...

CVE-2018-5390HIGH7.5same product

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prun...

CVE-2026-20182CRITICAL10.0⚠ KEVPL ✓same vendor

Cisco Catalyst SD-WAN — pominięcie uwierzytelnienia z dostępem administracyjnym

CVE-2026-20131CRITICAL10.0⚠ KEVPL ✓same vendor

RCE przez insecure deserialization w Cisco Secure Firewall Management Center