Critical Cisco bug exposes Expressway gateways to CSRF attacks
ID: 3a1461d3-0cf5-54b5-a4be-1d25c20565f2
STIX ID: report--3a1461d3-0cf5-54b5-a4be-1d25c20565f2
Feed Name: Bleeping Computer
Cisco released patches for three CSRF vulnerabilities in its Expressway Series collaboration gateways (CVE-2024-20252, CVE-2024-20254, CVE-2024-20255). Two are rated critical and can be exploited remotely against default configurations to perform actions with an affected user’s privileges (including administrative changes), while the third can cause configuration changes and DoS; affected 14.0 releases are fixed in 14.3.4 and earlier releases should be migrated. Cisco reports no evidence of public exploit or active attacks, and will not patch end-of-support VCS gateways.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
