CVE-2024-20252

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF)

Severity
Critical 9.6
CVSS 3.1
Exploited
Not listed
EPSS
0.008
54.5th percentile
Discovered by
Vendor
Published by the vendor
Published
Feb 7, 2024
Assigned by cisco

Description

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.

Weakness: CWE-352

Affected products

Vendor Product Category Matched by
Cisco Cisco TelePresence Other Products cna-assigner
Vendor-reported affected versions (2)
  • Cisco · Cisco TelePresence Video Communication Server (VCS) Expressway
  • cisco · telepresence_video_communication_server_software