iTnews
  • Home
  • News
  • Technology
  • Security

Cisco unified comms gateways have API bug

By Richard Chirgwin
Feb 8 2024 5:03PM

Need patching against CSRF vulnerabilities.

Cisco has disclosed three API vulnerabilities in its Cisco Expressway Series of unified communications gateways, which expose affected devices to an attacker performing “arbitrary actions”.

Cisco unified comms gateways have API bug

Cisco’s advisory states that the cross-site request forgery (CSRF) bugs affect Cisco Expressway Control and Cisco Expressway Edge devices.

The three vulnerabilities in Cisco’s advisory, CVE-2024-20252, CVE-2024-20254, and CVE-2024-20255 are all CSRF bugs in the devices’ web management interface.

All three vulnerabilities are exploited by persuading an API user to follow a crafted link, the advisory said.

A successful exploit lets the attacker “perform arbitrary actions” with the privilege of the affected user, all the way up to admin privileges.

CVE-2024-20252 and CVE-2024-20254 (both have a CVSS score of 9.6) allow a successful attacker to modify the system configuration and create new privileged accounts.

The lower-rated CVE-2024-20255 (CVSS score 8.2) also allows an attacker to execute some system commands, but only exposes the victim to a denial-of-service attack.

The vulnerabilities affect Cisco Expressway Series older than 14.0 (which needs an upgrade to a later, fixed version), 14.0 (fixed in 14.3.4), and 15.0 (fixed in 15.0.0).

The bugs also affect the end-of-life Cisco TelePresence video communication server, which will not receive a patch.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cisconetworkingsecurity

Related Articles

  • AI is a force multiplier in the fight against cybercriminals AI is a force multiplier in the fight against cybercriminals
  • Nissan A/NZ's outsourced cyber incident call centre breached Nissan A/NZ's outsourced cyber incident call centre breached
  • Western Sydney Uni discloses January "IT network" breach Western Sydney Uni discloses January "IT network" breach
  • Macquarie's banking CISO headed to Endeavour Group Macquarie's banking CISO headed to Endeavour Group

Partner Content

Working “out in the open” with a psychological safety net
Partner Content Working “out in the open” with a psychological safety net
Cloud Covered
Cloud Covered
Why you should use the cloud to secure your cloud
Partner Content Why you should use the cloud to secure your cloud
AI ‘thought partner’ poised to augment Australian workers
Partner Content AI ‘thought partner’ poised to augment Australian workers

Sponsored Whitepapers

Gain an independent witness with body-worn cameras
Gain an independent witness with body-worn cameras
Gain an independent witness with body-worn cameras
Gain an independent witness with body-worn cameras
Trust Imperative 4.0
Trust Imperative 4.0
Centralized Remote Connectivity for State & Local Government
Centralized Remote Connectivity for State & Local Government
Global Employee Experience Trends Report
Global Employee Experience Trends Report
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Macquarie Uni to spend up to $700m on 10-year digital transformation

Macquarie Uni to spend up to $700m on 10-year digital transformation

Nissan A/NZ's outsourced cyber incident call centre breached

Nissan A/NZ's outsourced cyber incident call centre breached

Digital ID bill passes parliament

Digital ID bill passes parliament

Macquarie's banking CISO headed to Endeavour Group

Macquarie's banking CISO headed to Endeavour Group

Digital Nation

How eBay uses interaction analytics to improve CX
How eBay uses interaction analytics to improve CX
COVER STORY: What AI regulation might look like in Australia
COVER STORY: What AI regulation might look like in Australia
More than half of loyalty members concerned about their data
More than half of loyalty members concerned about their data
Health tech startup Kismet raises $4m in pre-seed funding
Health tech startup Kismet raises $4m in pre-seed funding
State of Security 2023
State of Security 2023
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.