Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.
The attacker prepares a malicious website or crafted link which, when visited by an authenticated user (e.g., an administrator), causes unauthorized HTTP requests to be sent to the affected device. The device, without properly verifying the origin of the request, treats it as legitimate and executes the commands contained within it in the context of the victim's session. In this way, the attacker can perform arbitrary administrative actions without possessing their own credentials.
An attacker can perform arbitrary, unauthorized actions on the device in the context of the logged-in user's privileges — including configuration modification, creation of administrative accounts, or compromise of system confidentiality, integrity, and availability.
Security patches available from the manufacturer should be applied in accordance with references published in the Cisco Security Advisory bulletin (cisco-sa-expressway-csrf-KnnZDMj3). Additionally, it is recommended to restrict access to the administrative interface exclusively to trusted networks and to implement multi-factor authentication mechanisms.
Cisco Expressway Control (Expressway-C), Cisco Expressway Edge (Expressway-E), and Cisco TelePresence Video Communication Server (VCS) — specific versions indicated in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HCisco Expressway
APPCisco≤ 15.0
Related vulnerabilities
CSRF w Cisco Expressway i TelePresence VCS umożliwiający zdalne działania
Cisco Expressway / TelePresence VCS — path traversal i null byte poisoning w API
Cisco Expressway/VCS – nadpisywanie plików i null byte poisoning w API
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server c...
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prun...