CVE-2022-20853

HIGH EPSS 45.0%
Published Nov 15, 20241y ago · Modified Jun 17, 20261w ago
7.4 CVSS 3.1
High
Find Similar
Published Nov 15, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user of the REST API to follow a crafted link. A successful exploit could allow the attacker to cause the affected system to reload. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. 

CVSS Details

Base Score
7.4
Exploitability
2.8
Impact
4.0
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
45.0% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-352 Cross-Site Request Forgery (CSRF) Authentication

Affected Products 59

VendorProductVersionRange
ciscotelepresence_video_communication_serverx8.1any
ciscotelepresence_video_communication_serverx8.1.1any
ciscotelepresence_video_communication_serverx8.1.2any
ciscotelepresence_video_communication_serverx8.2any
ciscotelepresence_video_communication_serverx8.2.1any
ciscotelepresence_video_communication_serverx8.2.2any
ciscotelepresence_video_communication_serverx8.5any
ciscotelepresence_video_communication_serverx8.5.1any
ciscotelepresence_video_communication_serverx8.5.2any
ciscotelepresence_video_communication_serverx8.5.3any
ciscotelepresence_video_communication_serverx8.6any
ciscotelepresence_video_communication_serverx8.6.1any
ciscotelepresence_video_communication_serverx8.7any
ciscotelepresence_video_communication_serverx8.7.1any
ciscotelepresence_video_communication_serverx8.7.2any
ciscotelepresence_video_communication_serverx8.7.3any
ciscotelepresence_video_communication_serverx8.8any
ciscotelepresence_video_communication_serverx8.8.1any
ciscotelepresence_video_communication_serverx8.8.2any
ciscotelepresence_video_communication_serverx8.8.3any
ciscotelepresence_video_communication_serverx8.9any
ciscotelepresence_video_communication_serverx8.9.1any
ciscotelepresence_video_communication_serverx8.9.2any
ciscotelepresence_video_communication_serverx8.10.0any
ciscotelepresence_video_communication_serverx8.10.1any
ciscotelepresence_video_communication_serverx8.10.2any
ciscotelepresence_video_communication_serverx8.10.3any
ciscotelepresence_video_communication_serverx8.10.4any
ciscotelepresence_video_communication_serverx8.11.0any
ciscotelepresence_video_communication_serverx8.11.1any
ciscotelepresence_video_communication_serverx8.11.2any
ciscotelepresence_video_communication_serverx8.11.3any
ciscotelepresence_video_communication_serverx8.11.4any
ciscotelepresence_video_communication_serverx12.5.0any
ciscotelepresence_video_communication_serverx12.5.1any
ciscotelepresence_video_communication_serverx12.5.2any
ciscotelepresence_video_communication_serverx12.5.3any
ciscotelepresence_video_communication_serverx12.5.4any
ciscotelepresence_video_communication_serverx12.5.5any
ciscotelepresence_video_communication_serverx12.5.6any
ciscotelepresence_video_communication_serverx12.5.7any
ciscotelepresence_video_communication_serverx12.5.8any
ciscotelepresence_video_communication_serverx12.5.9any
ciscotelepresence_video_communication_serverx12.6.0any
ciscotelepresence_video_communication_serverx12.6.1any
ciscotelepresence_video_communication_serverx12.6.2any
ciscotelepresence_video_communication_serverx12.6.3any
ciscotelepresence_video_communication_serverx12.6.4any
ciscotelepresence_video_communication_serverx12.7.0any
ciscotelepresence_video_communication_serverx12.7.1any
ciscotelepresence_video_communication_serverx14.0.0any
ciscotelepresence_video_communication_serverx14.0.1any
ciscotelepresence_video_communication_serverx14.0.2any
ciscotelepresence_video_communication_serverx14.0.3any
ciscotelepresence_video_communication_serverx14.0.4any
ciscotelepresence_video_communication_serverx14.0.5any
ciscotelepresence_video_communication_serverx14.0.6any
ciscotelepresence_video_communication_serverx14.0.7any
ciscotelepresence_video_communication_serverx14.0.8any

References 4

  • sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-thinrcpt-xss-gSj4CecU
    Not Applicable
  • sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-priv-esc-SEjz69dv
    Not Applicable
  • sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-sqpsSfY6
    Vendor Advisory
  • sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-prv-esc-8PdRU8t8
    Not Applicable

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.