We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-20252



Assignercisco
Reserved2023-11-08
Published2024-02-07
Updated2024-08-01

Description

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.



CRITICAL: 9.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Product status

X8.5.1
affected

X8.5.3
affected

X8.5
affected

X8.6.1
affected

X8.6
affected

X8.1.1
affected

X8.1.2
affected

X8.1
affected

X8.2.1
affected

X8.2.2
affected

X8.2
affected

X8.7.1
affected

X8.7.2
affected

X8.7.3
affected

X8.7
affected

X8.8.1
affected

X8.8.2
affected

X8.8.3
affected

X8.8
affected

X8.9.1
affected

X8.9.2
affected

X8.9
affected

X8.10.0
affected

X8.10.1
affected

X8.10.2
affected

X8.10.3
affected

X8.10.4
affected

X12.5.8
affected

X12.5.9
affected

X12.5.0
affected

X12.5.2
affected

X12.5.7
affected

X12.5.3
affected

X12.5.4
affected

X12.5.5
affected

X12.5.1
affected

X12.5.6
affected

X12.6.0
affected

X12.6.1
affected

X12.6.2
affected

X12.6.3
affected

X12.6.4
affected

X12.7.0
affected

X12.7.1
affected

X8.11.1
affected

X8.11.2
affected

X8.11.4
affected

X8.11.3
affected

X8.11.0
affected

X14.0.1
affected

X14.0.3
affected

X14.0.2
affected

X14.0.4
affected

X14.0.5
affected

X14.0.6
affected

X14.0.7
affected

X14.0.8
affected

X14.0.9
affected

X14.0.10
affected

X14.0.11
affected

X14.2.1
affected

X14.2.2
affected

X14.2.5
affected

X14.2.6
affected

X14.2.0
affected

X14.2.7
affected

X14.3.0
affected

X14.3.1
affected

X14.3.2
affected

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-KnnZDMj3 (cisco-sa-expressway-csrf-KnnZDMj3)

cve.org CVE-2024-20252

nvd.nist.gov CVE-2024-20252

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-20252
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.