CVE-2024-20462
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability is due to incorrect sanitization of HTML content from an affected device. A successful exploit could allow the attacker to view passwords that belong to other users.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.16%
- CWE
- CWE-257
- Published
- 2024-10-16
- Last modified
- 2026-03-13
Affected products
- Cisco Cisco Analog Telephone Adaptor (ATA) Software
- Cisco Cisco Analog Telephone Adaptor (ATA) Software
- Cisco Cisco Analog Telephone Adaptor (ATA) Software
- Cisco Cisco Analog Telephone Adaptor (ATA) Software
- Cisco Cisco Analog Telephone Adaptor (ATA) Software
- Cisco Cisco Analog Telephone Adaptor (ATA) Software
- Cisco Cisco Analog Telephone Adaptor (ATA) Software
- Cisco Cisco Analog Telephone Adaptor (ATA) Software
Weakness type
Related vulnerabilities
- CVE-2026-69297 — Windows DHCP Server Information Disclosure Vulnerability
- CVE-2026-80176 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-65309 — Storage of passwords in a reversible format
- CVE-2026-1836 — Stored credentials in Redmine
- CVE-2026-22574 — A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through...
- CVE-2026-22576 — A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through...
- CVE-2025-8095 — Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge
- CVE-2016-15058 — Hirschmann HiLCOS Classic Platform Password Exposure via SNMP