Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.
An attacker, exploiting the CSRF vulnerability, can trick a logged-in user (e.g., an administrator) into visiting a crafted website or clicking on a malicious link. The victim's browser then sends an unauthorized HTTP request to the vulnerable device, which treats it as legitimate because it originates from an authenticated session. As a result, the attacker can instruct the execution of arbitrary operations on behalf of the victim without their knowledge or consent. The vulnerability affects both Cisco Expressway Control (Expressway-C) and Cisco Expressway Edge (Expressway-E) devices.
An attacker can perform arbitrary, unauthorized actions on the vulnerable device with the privileges of the attacked user, which may lead to complete device takeover, violation of data confidentiality and integrity, and disruption of its availability.
Apply patches available from the manufacturer in accordance with references published at: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-KnnZDMj3. Additionally, it is recommended to restrict access to device management interfaces exclusively to trusted networks and to implement administrative session protection mechanisms.
Cisco Expressway Control (Expressway-C), Cisco Expressway Edge (Expressway-E), and Cisco TelePresence Video Communication Server (VCS) — versions indicated in the manufacturer's references.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HCisco Expressway
APPCisco≤ 15.0
Related vulnerabilities
CSRF w Cisco Expressway Series i TelePresence VCS — nieautoryzowane działania
Cisco Expressway / TelePresence VCS — path traversal i null byte poisoning w API
Cisco Expressway/VCS – nadpisywanie plików i null byte poisoning w API
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server c...
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prun...