iTnews Asia
  • Home
  • News
  • Networking

Cisco unified comms gateways have API bug

Cisco unified comms gateways have API bug

Need patching against CSRF vulnerabilities.

By Richard Chirgwin on Feb 9, 2024 9:11AM

Cisco has disclosed three API vulnerabilities in its Cisco Expressway Series of unified communications gateways, which expose affected devices to an attacker performing “arbitrary actions”.

Cisco’s advisory states that the cross-site request forgery (CSRF) bugs affect Cisco Expressway Control and Cisco Expressway Edge devices.

The three vulnerabilities in Cisco’s advisory, CVE-2024-20252, CVE-2024-20254, and CVE-2024-20255 are all CSRF bugs in the devices’ web management interface.

All three vulnerabilities are exploited by persuading an API user to follow a crafted link, the advisory said.

A successful exploit lets the attacker “perform arbitrary actions” with the privilege of the affected user, all the way up to admin privileges.

CVE-2024-20252 and CVE-2024-20254 (both have a CVSS score of 9.6) allow a successful attacker to modify the system configuration and create new privileged accounts.

The lower-rated CVE-2024-20255 (CVSS score 8.2) also allows an attacker to execute some system commands, but only exposes the victim to a denial-of-service attack.

The vulnerabilities affect Cisco Expressway Series older than 14.0 (which needs an upgrade to a later, fixed version), 14.0 (fixed in 14.3.4), and 15.0 (fixed in 15.0.0).

The bugs also affect the end-of-life Cisco TelePresence video communication server, which will not receive a patch.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cisco networking security

Related Articles

  • Proofpoint CEO: A tool-based approach for cybersecurity is impractical
  • Akamai: AI-security is both a security imperative and an economic necessity
  • The real-life Tom & Jerry chase
  • How can we bolster our resilience against AI-enabled e-mail attacks?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Shangri-La Group's Jen hotels implement smart check-in kiosks

Shangri-La Group's Jen hotels implement smart check-in kiosks

TIME dotCom to use cyber security mesh platform

TIME dotCom to use cyber security mesh platform

Thailand launches first 5G smart hospital in ASEAN

Thailand launches first 5G smart hospital in ASEAN

Jaguar Land Rover ties up with Nvidia to develop autonomous vehicles

Jaguar Land Rover ties up with Nvidia to develop autonomous vehicles

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.