CVE-2024-20497
- EPSS 0.09%
- Published 04.09.2024 17:15:13
- Last modified 12.08.2025 23:51:41
A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is due to inadequate authorization checks for Mobile and Remote Access (M...
CVE-2024-20254
- EPSS 5.16%
- Published 07.02.2024 17:15:10
- Last modified 21.11.2024 08:52:07
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affe...
CVE-2024-20255
- EPSS 0.76%
- Published 07.02.2024 17:15:10
- Last modified 21.11.2024 08:52:07
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerab...
CVE-2024-20252
- EPSS 7.36%
- Published 07.02.2024 17:15:09
- Last modified 21.11.2024 08:52:06
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affe...
CVE-2023-44487
- EPSS 94.44%
- Published 10.10.2023 14:15:10
- Last modified 11.06.2025 17:29:54
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2022-20812
- EPSS 0.11%
- Published 06.07.2022 21:15:11
- Last modified 21.11.2024 06:43:36
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning...
CVE-2022-20813
- EPSS 0.09%
- Published 06.07.2022 21:15:11
- Last modified 21.11.2024 06:43:36
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning...
- EPSS 0.67%
- Published 18.08.2021 20:15:07
- Last modified 21.11.2024 06:11:02
A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operat...
- EPSS 1.1%
- Published 18.08.2021 20:15:07
- Last modified 21.11.2024 06:11:02
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the...
CVE-2020-3482
- EPSS 0.2%
- Published 18.11.2020 19:15:12
- Last modified 21.11.2024 05:31:09
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The vulnera...