Cisco Issues Security Advisory for Cross-Site Request Forgery Vulnerability
CVE-2022-20853

7.4HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
15 November 2024

Summary

This vulnerability affects the REST API of Cisco Expressway Series and Cisco TelePresence VCS, allowing unauthenticated, remote attackers to potentially execute cross-site request forgery (CSRF) attacks on affected systems. Insufficient CSRF protections in the web-based management interface enable an attacker to trick a user into clicking a specially crafted link. This could lead to unauthorized actions being performed on the affected system, including the possibility of causing it to reload. Cisco has issued software updates to mitigate this issue, with no available workarounds.

Affected Version(s)

Cisco TelePresence Video Communication Server (VCS) Expressway X8.11.2

Cisco TelePresence Video Communication Server (VCS) Expressway X8.6

Cisco TelePresence Video Communication Server (VCS) Expressway X8.11.3

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.