{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/finesse/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:cisco:ios_xe:17.1.1:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.1.1a:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.1.1s:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.1.1t:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.1.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.2.1:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.2.1a:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.2.1r:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.2.1v:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.2.2:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.2.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.3.1:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.3.1a:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.3.1w:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.3.1x:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.3.1z:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.3.2:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.3.2a:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.3.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:17.3.4:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2024-20455"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Finesse","Unified CCE","Unified CCX"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Cisco"],"content_html":"\u003cp\u003eCisco has disclosed a critical Server-Side Request Forgery (SSRF) vulnerability, identified as CVE-2024-20455, affecting Cisco Finesse, Cisco Unified Contact Center Enterprise (Unified CCE), and Cisco Unified Contact Center Express (Unified CCX). The vulnerability exists due to insufficient validation of user-supplied input provided to the application, allowing an unauthenticated, remote attacker to manipulate the backend server into performing unauthorized HTTP requests. By crafting specific requests, an attacker can bypass access controls to reach internal resources that are otherwise not accessible from the public internet. This flaw poses a significant risk to organizations as it may lead to the exfiltration of sensitive configuration data, internal metadata, or internal service responses that aid in further reconnaissance or lateral movement within the network. Defenders should prioritize patching, as this vulnerability requires no specialized authentication or prior access to the targeted systems.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized actors to perform SSRF attacks, leading to the exposure of sensitive internal information and reconnaissance of internal network segments. This exposes critical contact center infrastructure to potential data theft and increased risk of follow-on attacks against backend components, impacting the confidentiality of organizational data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the application of vendor-supplied patches for CVE-2024-20455 across all affected Cisco Unified Communications products. Configure network-level egress filtering to restrict internal server-to-server communication initiated by these specific applications to only required destinations. Implement strict input validation and access controls on any application endpoints that handle URI-based parameters.\u003c/p\u003e\n","date_modified":"2026-10-08T13:10:19Z","date_published":"2026-10-08T13:10:19Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cisco-ssrf/","summary":"An unauthenticated, remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in Cisco Finesse, Unified CCE, and Unified CCX to gain unauthorized access to internal resources and disclose sensitive information.","title":"SSRF Vulnerability in Cisco Finesse, Unified CCE, and Unified CCX","url":"https://feed.craftedsignal.io/briefs/2026-10-cisco-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Finesse","version":"https://jsonfeed.org/version/1.1"}