Security News > 2024 > February > Critical Patches Released for New Flaws in Cisco, Fortinet, VMware Products

Critical Patches Released for New Flaws in Cisco, Fortinet, VMware Products
2024-02-08 05:10

Cisco, Fortinet, and VMware have released security fixes for multiple security vulnerabilities, including critical weaknesses that could be exploited to perform arbitrary actions on affected devices. The first set from Cisco consists of three flaws – CVE-2024-20252 and CVE-2024-20254 (CVSS score: 9.6) and CVE-2024-20255 (CVSS score: 8.2) – impacting Cisco Expressway Series that could allow an


News URL

https://thehackernews.com/2024/02/critical-patches-released-for-new-flaws.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-20255 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Expressway 14.0/14.0.7
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system.
network
low complexity
cisco CWE-352
7.1
2024-02-07 CVE-2024-20254 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Expressway 14.0/14.0.7
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device.
network
low complexity
cisco CWE-352
8.8
2024-02-07 CVE-2024-20252 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Expressway 14.0/14.0.7
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device.
network
low complexity
cisco CWE-352
8.8