Expressway
Vendor:
First CVE: Dec 14, 2016 · Active for 9 years
14
Total CVEs
More Total CVEs than 91% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Expressway over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 14, 2016
9 years ago
Most Recent CVE
Feb 7, 2024
899 days ago
CVE Severity & Scoring
Expressway14 CVEs
36%
64%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low1 (7.1%)
High3 (21.4%)
None10 (71.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2018-5390HIGH Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of | Aug 6, 2018 | 7.5 | 66 | NO | NO |
CVE-2024-20252HIGH Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site re | Feb 7, 2024 | 8.8 | 29 | NO | NO |
CVE-2024-20254HIGH Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site re | Feb 7, 2024 | 8.8 | 28 | NO | NO |
CVE-2022-20812MEDIUM Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remot | Jul 6, 2022 | 6.5 | 24 | NO | NO |
CVE-2021-34716HIGH A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attack | Aug 18, 2021 | 7.2 | 23 | NO | NO |
CVE-2021-34715HIGH A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker | Aug 18, 2021 | 7.2 | 23 | NO | NO |
CVE-2024-20255HIGH A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site | Feb 7, 2024 | 7.1 | 22 | NO | NO |
CVE-2022-20813MEDIUM Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remot | Jul 6, 2022 | 5.9 | 22 | NO | NO |
CVE-2020-3596HIGH A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote a | Oct 8, 2020 | 7.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
1 CVE
7.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Expressway
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| x8.8.3 | 1 | 6.5 | 2.0% | 0 | 0 |
| x8.8.1 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.8.0 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.7.3 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.7.2 | 2 | 7.5 | 2.8% | 0 | 0 |
| x8.7.1 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.7.0 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.6.1 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.6.0 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.5_base | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.5.3 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.5.2 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.5.1 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.5.0 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.5 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.2_base | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.2.2 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.2.1 | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.1_base | 1 | 8.6 | 3.5% | 0 | 0 |
| x8.1.2 | 1 | 8.6 | 3.5% | 0 | 0 |