CVE Database
/

CVE-2019-1679

Back to search

CVE-2019-1679

Published: Feb 7, 2019

Modified: Nov 21, 2024

PUBLISHED

CVSS v3.0

5.0

MEDIUM

Description

A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host. This type of attack is commonly referred to as server-side request forgery (SSRF). The vulnerability is due to insufficient access controls for the REST API of Cisco Expressway Series and Cisco TelePresence VCS. An attacker could exploit this vulnerability by submitting a crafted HTTP request to the affected server. Versions prior to XC4.3.4 are affected.

VendorProductVersions

Cisco

Cisco TelePresence Conductor

affected
unspecified - < XC4.3.4

Cisco

Cisco Expressway Series

affected
unspecified - < XC4.3.4

Cisco

Cisco TelePresence Video Communication Server

affected
unspecified - < XC4.3.4

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now