Security News > 2024 > February > Critical Patches Released for New Flaws in Cisco, Fortinet, VMware Products

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-20255 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Expressway 14.0/14.0.7/15.0
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system.
network
low complexity
cisco CWE-352
7.1
2024-02-07 CVE-2024-20254 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Expressway 14.0/14.0.7/15.0
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device.
network
low complexity
cisco CWE-352
8.8
2024-02-07 CVE-2024-20252 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Expressway 14.0/14.0.7/15.0
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device.
network
low complexity
cisco CWE-352
8.8