QID 38878
Date Published: 2022-10-10
QID 38878: Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities (cisco-sa-expressway-csrf-sqpsSfY6) (CVE-2022-20853)
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow a remote attacker to bypass certificate validation or conduct cross-site request forgery attacks on an affected device.
Affected Products
Cisco Expressway Series and Cisco TelePresence VCS prior to version 14.2
QID Detection Logic (Unauthenticated):
The check matches version of Cisco TelePresence Video Communication Server Expressway on the exposed banner information under the SIP banner.
Software could allow a remote attacker to bypass certificate validation or conduct cross-site request forgery attacks on an affected device.
Customers are advised to refer to cisco-sa-expressway-csrf-sqpsSfY6 for more information.
- cisco-sa-expressway-csrf-sqpsSfY6 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-sqpsSfY6
CVEs related to QID 38878
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-expressway-csrf-sqpsSfY6 |
|