CVE-2019-1679 (CNNVD-201902-306)
中文标题:
Cisco TelePresence Conductor、Expressway Series和TelePresence VCS 代码问题漏洞
英文标题:
Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server REST API Server-Side Request Forgery Vulnerability
漏洞描述
中文描述:
Cisco Expressway Series等都是美国思科(Cisco)公司的产品。Cisco Expressway Series是一款用于统一通信的高级协作网关。Cisco TelePresence Video Communication Server(VCS)是一款视频通信服务器。Cisco TelePresence Conductor是一套视频会议资源管理解决方案。 Cisco TelePresence Conductor、Expressway Series和TelePresence VCS 中存在代码问题漏洞,该漏洞源于程序没有对REST API执行充分的访问控制。远程攻击者可利用该漏洞向任意主机发送HTTP请求。
英文描述:
A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host. This type of attack is commonly referred to as server-side request forgery (SSRF). The vulnerability is due to insufficient access controls for the REST API of Cisco Expressway Series and Cisco TelePresence VCS. An attacker could exploit this vulnerability by submitting a crafted HTTP request to the affected server. Versions prior to XC4.3.4 are affected.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco TelePresence Conductor | - | < XC4.3.4 | - |
cpe:2.3:a:cisco:cisco_telepresence_conductor:*:*:*:*:*:*:*:*
|
| Cisco | Cisco Expressway Series | - | < XC4.3.4 | - |
cpe:2.3:a:cisco:cisco_expressway_series:*:*:*:*:*:*:*:*
|
| Cisco | Cisco TelePresence Video Communication Server | - | < XC4.3.4 | - |
cpe:2.3:a:cisco:cisco_telepresence_video_communication_server:*:*:*:*:*:*:*:*
|
| cisco | telepresence_video_communication_server | * | - | - |
cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:*:*:*:*
|
| cisco | telepresence_conductor | * | - | - |
cpe:2.3:a:cisco:telepresence_conductor:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-1679 |
2025-11-11 15:20:08 | 2025-11-11 07:35:37 |
| NVD | nvd_CVE-2019-1679 |
2025-11-11 14:56:20 | 2025-11-11 07:44:09 |
| CNNVD | cnnvd_CNNVD-201902-306 |
2025-11-11 15:10:09 | 2025-11-11 07:54:20 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码问题
- cnnvd_id: 未提取 -> CNNVD-201902-306
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 3 -> 5
- data_sources: ['cve'] -> ['cve', 'nvd']