CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-20252

CVSS 9.6v3.1pub. 2024-02-07upd. 2024-11-21

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.

🤖 AI Analysis
How it works

The attacker prepares a malicious website or crafted link which, when visited by an authenticated user (e.g., an administrator), causes unauthorized HTTP requests to be sent to the affected device. The device, without properly verifying the origin of the request, treats it as legitimate and executes the commands contained within it in the context of the victim's session. In this way, the attacker can perform arbitrary administrative actions without possessing their own credentials.

Impact

An attacker can perform arbitrary, unauthorized actions on the device in the context of the logged-in user's privileges — including configuration modification, creation of administrative accounts, or compromise of system confidentiality, integrity, and availability.

Mitigation & patch

Security patches available from the manufacturer should be applied in accordance with references published in the Cisco Security Advisory bulletin (cisco-sa-expressway-csrf-KnnZDMj3). Additionally, it is recommended to restrict access to the administrative interface exclusively to trusted networks and to implement multi-factor authentication mechanisms.

Who is affected

Cisco Expressway Control (Expressway-C), Cisco Expressway Edge (Expressway-E), and Cisco TelePresence Video Communication Server (VCS) — specific versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Cisco Expressway

    APP
    Cisco
    ≤ 15.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-20254CRITICAL9.6PL ✓same product

CSRF w Cisco Expressway i TelePresence VCS umożliwiający zdalne działania

CVE-2022-20812CRITICAL9.0PL ✓same product

Cisco Expressway / TelePresence VCS — path traversal i null byte poisoning w API

CVE-2022-20813CRITICAL9.0PL ✓same product

Cisco Expressway/VCS – nadpisywanie plików i null byte poisoning w API

CVE-2024-20255HIGH8.2same product

A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server c...

CVE-2018-5390HIGH7.5same product

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prun...