Attacker Could Redirect Users to Malicious Web Page via Cisco Expressway Series Vulnerability

CVE-2024-20400
4.7MEDIUM

Key Information

Vendor
Cisco
Status
Cisco Telepresence Video Communication Server (vcs) Expressway
Vendor
CVE Published:
17 July 2024

Badges

👾 Exploit Exists

Summary

A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page. Note: Cisco Expressway Series refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices.

Affected Version(s)

Cisco TelePresence Video Communication Server (VCS) Expressway = X8.5.1

Cisco TelePresence Video Communication Server (VCS) Expressway = X8.5.3

Cisco TelePresence Video Communication Server (VCS) Expressway = X8.5

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

  • 👾

    Exploit exists.

Collectors

NVD DatabaseMitre Database
.