CVE-2024-20255
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CS
Description
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user of the REST API to follow a crafted link. A successful exploit could allow the attacker to cause the affected system to reload.
Weakness: CWE-352
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco TelePresence | Other Products | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco TelePresence Video Communication Server (VCS) Expressway
Vendor advisory
cisco-sa-expressway-csrf-KnnZDMj3
Cisco Expressway Series Cross-Site Request Forgery Vulnerabilities
Cisco’s rating: Critical (advisory CVSS 9.6) · Published Feb 7, 2024 · updated Feb 12, 2024 (revision 1.1)
Bug IDs: CSCwa25074 , CSCwa25099 , CSCwa25100
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from