CVE-2024-20255

A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CS

Severity
High 8.2
CVSS 3.1
Exploited
Not listed
EPSS
0.006
45.5th percentile
Discovered by
Vendor
Published by the vendor
Published
Feb 7, 2024
Assigned by cisco

Description

A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user of the REST API to follow a crafted link. A successful exploit could allow the attacker to cause the affected system to reload.

Weakness: CWE-352

Affected products

Vendor Product Category Matched by
Cisco Cisco TelePresence Other Products cna-assigner
Vendor-reported affected versions (1)
  • Cisco · Cisco TelePresence Video Communication Server (VCS) Expressway