CVE-2022-20853
CVSS 3.1 Score 7.4 of 10 (high)
Details
Published Nov 15, 2024
CWE ID 352
Summary
CVE-2022-20853 is a vulnerability affecting the REST API of Cisco Expressway Series and Cisco TelePresence VCS. An unauthenticated, remote attacker can exploit this issue through a cross-site request forgery (CSRF) attack, leading to system reloading. The root cause is insufficient CSRF protections in the web-based management interface. Users of the REST API are at risk, and a successful exploit could allow an attacker to manipulate affected systems. Cisco has released software updates to mitigate this vulnerability, but no workarounds are available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.