VDB

CISCO-SA-EXPRESSWAY-CSRF-KNNZDMJ3

CISCO-SA-EXPRESSWAY-CSRF-KNNZDMJ3 PUBLISHED CVSS 9.600000381469727 CRITICAL

Multiple vulnerabilities in the Cisco Expressway Series could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks, which could allow the attacker to perform arbitrary actions on an affected device. Note: Cisco Expressway Series refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

Risk Scores

CVSS v3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Cisco TelePresence Video Communication Server (VCS) Expressway

Timeline

  • Feb 7, 2024 CVE Published
  • Feb 12, 2024 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›