CVE-2024-20255

A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user of the REST API to follow a crafted link. A successful exploit could allow the attacker to cause the affected system to reload.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:expressway:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:52

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 8.2
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-KnnZDMj3 - Vendor Advisory () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-KnnZDMj3 - Vendor Advisory

15 Feb 2024, 15:54

Type Values Removed Values Added
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-KnnZDMj3 - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-KnnZDMj3 - Vendor Advisory
Summary
  • (es) Una vulnerabilidad en la API SOAP de Cisco Expressway Series y Cisco TelePresence Video Communication Server podría permitir que un atacante remoto no autenticado lleve a cabo un ataque de cross-site request forgery (CSRF) en un sistema afectado. Esta vulnerabilidad se debe a protecciones CSRF insuficientes para la interfaz de administración basada en web de un sistema afectado. Un atacante podría aprovechar esta vulnerabilidad persuadiendo a un usuario de la API REST para que siga un enlace manipulado. Un exploit exitoso podría permitir al atacante hacer que el sistema afectado se recargue.
First Time Cisco
Cisco expressway
CVSS v2 : unknown
v3 : 8.2
v2 : unknown
v3 : 7.1
CPE cpe:2.3:a:cisco:expressway:*:*:*:*:*:*:*:*

07 Feb 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-07 17:15

Updated : 2024-11-21 08:52


NVD link : CVE-2024-20255

Mitre link : CVE-2024-20255

CVE.ORG link : CVE-2024-20255


JSON object : View

Products Affected

cisco

  • expressway
CWE
CWE-352

Cross-Site Request Forgery (CSRF)