Expressway

Vendor:

First CVE: Dec 14, 2016 · Active for 9 years

14
Total CVEs
More Total CVEs than 91% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Expressway over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 14, 2016
9 years ago
Most Recent CVE
Feb 7, 2024
899 days ago

CVE Severity & Scoring

Expressway14 CVEs
All CVEs352,427 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low1 (7.1%)
High3 (21.4%)
None10 (71.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of
Aug 6, 20187.566NONO
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site re
Feb 7, 20248.829NONO
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site re
Feb 7, 20248.828NONO
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remot
Jul 6, 20226.524NONO
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attack
Aug 18, 20217.223NONO
A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker
Aug 18, 20217.223NONO
A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site
Feb 7, 20247.122NONO
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remot
Jul 6, 20225.922NONO
A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote a
Oct 8, 20207.522NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
1 CVE
7.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Expressway

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
x8.8.316.52.0%00
x8.8.118.63.5%00
x8.8.018.63.5%00
x8.7.318.63.5%00
x8.7.227.52.8%00
x8.7.118.63.5%00
x8.7.018.63.5%00
x8.6.118.63.5%00
x8.6.018.63.5%00
x8.5_base18.63.5%00
x8.5.318.63.5%00
x8.5.218.63.5%00
x8.5.118.63.5%00
x8.5.018.63.5%00
x8.518.63.5%00
x8.2_base18.63.5%00
x8.2.218.63.5%00
x8.2.118.63.5%00
x8.1_base18.63.5%00
x8.1.218.63.5%00