SSRF Vulnerability in Cisco Finesse, Unified CCE, and Unified CCX
An unauthenticated, remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in Cisco Finesse, Unified CCE, and Unified CCX to gain unauthorized access to internal resources and disclose sensitive information.
CVE search metadata
CVE search record: CVE-2024-20455. Severity: high. CVSS: 8.6. EPSS: 0.66%. KEV: no. Product: Finesse, Unified CCE, Unified CCX. Brief: SSRF Vulnerability in Cisco Finesse, Unified CCE, and Unified CCX. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cisco-ssrf/
Cisco has disclosed a critical Server-Side Request Forgery (SSRF) vulnerability, identified as CVE-2024-20455, affecting Cisco Finesse, Cisco Unified Contact Center Enterprise (Unified CCE), and Cisco Unified Contact Center Express (Unified CCX). The vulnerability exists due to insufficient validation of user-supplied input provided to the application, allowing an unauthenticated, remote attacker to manipulate the backend server into performing unauthorized HTTP requests. By crafting specific requests, an attacker can bypass access controls to reach internal resources that are otherwise not accessible from the public internet. This flaw poses a significant risk to organizations as it may lead to the exfiltration of sensitive configuration data, internal metadata, or internal service responses that aid in further reconnaissance or lateral movement within the network. Defenders should prioritize patching, as this vulnerability requires no specialized authentication or prior access to the targeted systems.
Impact
Successful exploitation of this vulnerability allows unauthorized actors to perform SSRF attacks, leading to the exposure of sensitive internal information and reconnaissance of internal network segments. This exposes critical contact center infrastructure to potential data theft and increased risk of follow-on attacks against backend components, impacting the confidentiality of organizational data.
Recommendation
Prioritize the application of vendor-supplied patches for CVE-2024-20455 across all affected Cisco Unified Communications products. Configure network-level egress filtering to restrict internal server-to-server communication initiated by these specific applications to only required destinations. Implement strict input validation and access controls on any application endpoints that handle URI-based parameters.
Immediate actions
Apply security patches for CVE-2024-20455 to all instances of Finesse, Unified CCE, and Unified CCX.
Mitigations
Implement strict egress filtering at the network perimeter for servers running affected Cisco software.
CVE-2024-20455