Cisco Issues Security Advisory for Cross-Site Request Forgery Vulnerability
CVE-2022-20853
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 15 November 2024
Summary
This vulnerability affects the REST API of Cisco Expressway Series and Cisco TelePresence VCS, allowing unauthenticated, remote attackers to potentially execute cross-site request forgery (CSRF) attacks on affected systems. Insufficient CSRF protections in the web-based management interface enable an attacker to trick a user into clicking a specially crafted link. This could lead to unauthorized actions being performed on the affected system, including the possibility of causing it to reload. Cisco has issued software updates to mitigate this issue, with no available workarounds.
Affected Version(s)
Cisco TelePresence Video Communication Server (VCS) Expressway X8.11.2
Cisco TelePresence Video Communication Server (VCS) Expressway X8.6
Cisco TelePresence Video Communication Server (VCS) Expressway X8.11.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved