CVE-2024-20252

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF)

Severity
Critical 9.6
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.008
56.6th percentile
Discovered by
Vendor
Vendor-published field
Published
Feb 7, 2024
Assigned by cisco

Description

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.

Weakness: CWE-352

Affected products

Vendor Product Category Matched by
Cisco Cisco TelePresence Other Products cna-assigner
Vendor-reported products (2)
  • Cisco · Cisco TelePresence Video Communication Server (VCS) Expressway
  • cisco · telepresence_video_communication_server_software

Vendor advisory

cisco-sa-expressway-csrf-KnnZDMj3

Cisco Expressway Series Cross-Site Request Forgery Vulnerabilities

Cisco’s rating: Critical (advisory CVSS 9.6) · Published Feb 7, 2024 · updated Feb 12, 2024 (revision 1.1)

Bug IDs: CSCwa25074 , CSCwa25099 , CSCwa25100

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?