Cisco Issues Security Advisory for Cross-Site Request Forgery Vulnerability
CVE-2022-20853
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 15 November 2024
What is CVE-2022-20853?
This vulnerability affects the REST API of Cisco Expressway Series and Cisco TelePresence VCS, allowing unauthenticated, remote attackers to potentially execute cross-site request forgery (CSRF) attacks on affected systems. Insufficient CSRF protections in the web-based management interface enable an attacker to trick a user into clicking a specially crafted link. This could lead to unauthorized actions being performed on the affected system, including the possibility of causing it to reload. Cisco has issued software updates to mitigate this issue, with no available workarounds.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco TelePresence Video Communication Server (VCS) Expressway X8.11.2
Cisco TelePresence Video Communication Server (VCS) Expressway X8.6
Cisco TelePresence Video Communication Server (VCS) Expressway X8.11.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved