CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-20254

CVSS 9.6v3.1pub. 2024-02-07upd. 2024-11-21

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.

🤖 AI Analysis
How it works

An attacker, exploiting the CSRF vulnerability, can trick a logged-in user (e.g., an administrator) into visiting a crafted website or clicking on a malicious link. The victim's browser then sends an unauthorized HTTP request to the vulnerable device, which treats it as legitimate because it originates from an authenticated session. As a result, the attacker can instruct the execution of arbitrary operations on behalf of the victim without their knowledge or consent. The vulnerability affects both Cisco Expressway Control (Expressway-C) and Cisco Expressway Edge (Expressway-E) devices.

Impact

An attacker can perform arbitrary, unauthorized actions on the vulnerable device with the privileges of the attacked user, which may lead to complete device takeover, violation of data confidentiality and integrity, and disruption of its availability.

Mitigation & patch

Apply patches available from the manufacturer in accordance with references published at: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-KnnZDMj3. Additionally, it is recommended to restrict access to device management interfaces exclusively to trusted networks and to implement administrative session protection mechanisms.

Who is affected

Cisco Expressway Control (Expressway-C), Cisco Expressway Edge (Expressway-E), and Cisco TelePresence Video Communication Server (VCS) — versions indicated in the manufacturer's references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Cisco Expressway

    APP
    Cisco
    ≤ 15.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-20252CRITICAL9.6PL ✓same product

CSRF w Cisco Expressway Series i TelePresence VCS — nieautoryzowane działania

CVE-2022-20812CRITICAL9.0PL ✓same product

Cisco Expressway / TelePresence VCS — path traversal i null byte poisoning w API

CVE-2022-20813CRITICAL9.0PL ✓same product

Cisco Expressway/VCS – nadpisywanie plików i null byte poisoning w API

CVE-2024-20255HIGH8.2same product

A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server c...

CVE-2018-5390HIGH7.5same product

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prun...