VendorsCiscoexpresswayany version
Vulnerabilities

Cisco Expressway any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2024-20252
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.
Published 2024-02-07 · Modified
9.6EPSS 0.008
CVE-2024-20254
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.
Published 2024-02-07 · Modified
9.6EPSS 0.008
CVE-2021-34716
Cisco Expressway Series and TelePresence Video Communication Server Remote Code Execution Vulnerability
Published 2021-08-18 · Modified
9.0EPSS 0.024
CVE-2022-20812
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Published 2022-07-06 · Modified
9.0EPSS 0.019
CVE-2022-20813
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Published 2022-07-06 · Modified
9.0EPSS 0.011
CVE-2021-34715
Cisco Expressway Series and TelePresence Video Communication Server Image Verification Vulnerability
Published 2021-08-18 · Modified
9.0EPSS 0.011
CVE-2024-20255
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user of the REST API to follow a crafted link. A successful exploit could allow the attacker to cause the affected system to reload.
Published 2024-02-07 · Modified
8.2EPSS 0.006
CVE-2020-3596
Cisco Expressway Series and TelePresence Video Communication Server Denial of Service Vulnerability
Published 2020-10-08 · Modified
7.8EPSS 0.012
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2020-3482
Cisco Expressway Software Unauthorized Access Information Disclosure Vulnerability
Published 2020-11-18 · Modified
6.5EPSS 0.014
CVE-2017-12287
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system to restart unexpectedly, resulting in a temporary denial of service (DoS) condition. The vulnerability is due to incomplete input validation of URL requests by the REST API of the affected software. An attacker could exploit this vulnerability by sending a crafted URL to the REST API of the affected software on an affected system. A successful exploit could allow the attacker to cause the CDB process on the affected system to restart unexpectedly, resulting in a temporary DoS condition. Cisco Bug IDs: CSCve77571.
Published 2017-10-19 · Modified
4.3EPSS 0.016