Attacker Could Redirect Users to Malicious Web Page via Cisco Expressway Series Vulnerability
Key Information
- Vendor
- Cisco
- Status
- Cisco Telepresence Video Communication Server (vcs) Expressway
- Vendor
- CVE Published:
- 17 July 2024
Badges
Summary
A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page. Note: Cisco Expressway Series refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices.
Affected Version(s)
Cisco TelePresence Video Communication Server (VCS) Expressway = X8.5.1
Cisco TelePresence Video Communication Server (VCS) Expressway = X8.5.3
Cisco TelePresence Video Communication Server (VCS) Expressway = X8.5
CVSS V3.1
Timeline
Vulnerability published.
Vulnerability Reserved.
- 👾
Exploit exists.