Cisco Mobility Express Software Cross-Site Request Forgery Vulnerability
Published Apr 15, 2020
6.5
MEDIUMCVSS 3.1
EPSS 0.50%
Description
A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user with an active session on an affected device to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions, including modifying the configuration, with the privilege level of the user.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Cisco | Cisco Mobility Express | n/a |
|
Configuration 1
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 2
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 3
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 4
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 5
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 6
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 7
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 8
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 9
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 10
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 11
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 12
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 13
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 14
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 15
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 16
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
Configuration 17
- ≥ 8.0 · < 8.8.130.0
- 8.10\(1.255\)
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-24532 Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mob-exp-csrf-b8tFec24 vendor-advisoryx_refsource_CISCOVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-24532 | Advisory | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mob-exp-csrf-b8tFec24 | vendor-advisoryx_refsource_CISCOVendor Advisory |
Change history (0)
No recorded changes yet.