Cross-site request forgery in Cisco Systems, Inc products - CVE-2019-1679

 

Cross-site request forgery in Cisco Systems, Inc products - CVE-2019-1679

Published: February 7, 2019


Vulnerability identifier: #VU17433
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2019-1679
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient access controls for the REST API of Cisco Expressway Series and Cisco TelePresence VCS. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Affected software

Cisco TelePresence Video Communication Server
Telepresence Conductor
Cisco Expressway

How to mitigate CVE-2019-1679

Install updates from vendor's website.

Cisco TelePresence Video Communication Server - update to X12.5
Telepresence Conductor - update to

External References

Related Security Bulletins