CVE-2019-1872 (CNNVD-201906-154)
中文标题:
Cisco Expressway Series和Cisco TelePresence Video Communication Server 代码问题漏洞
英文标题:
Cisco TelePresence Video Communication Server and Cisco Expressway Series Server-Side Request Forgery Vulnerability
漏洞描述
中文描述:
Cisco Expressway Series和Cisco TelePresence Video Communication Server(VCS)都是美国思科(Cisco)公司的产品。Cisco Expressway Series是一款用于统一通信的高级协作网关。Cisco TelePresence Video Communication Server是一款视频通信服务器。 Cisco Expressway Series和Cisco TelePresence VCS x12.5之前版本中存在代码问题漏洞。该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。
英文描述:
A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests. The vulnerability is due to improper restrictions on network services in the affected software. An attacker could exploit this vulnerability by sending malicious requests to the affected system. A successful exploit could allow the attacker to send arbitrary network requests sourced from the affected system.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco TelePresence Video Communication Server (VCS) | - | < X12.5 | - |
cpe:2.3:a:cisco:cisco_telepresence_video_communication_server_(vcs):*:*:*:*:*:*:*:*
|
| cisco | telepresence_video_communication_server | * | - | - |
cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-1872 |
2025-11-11 15:20:09 | 2025-11-11 07:35:40 |
| NVD | nvd_CVE-2019-1872 |
2025-11-11 14:56:23 | 2025-11-11 07:44:11 |
| CNNVD | cnnvd_CNNVD-201906-154 |
2025-11-11 15:10:13 | 2025-11-11 07:54:36 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码问题
- cnnvd_id: 未提取 -> CNNVD-201906-154
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']