02-08-2024 10:05 AM
Hello,
the Cisco Security Advisory raised yesterday relates to bugs CSCwa25099, CSCwa25100 and CSCwa25074:
and basically mention: "This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system."
and also mention that there is no workaround, must upgrade to a fixed release.
If the bug is specific to the web-based management, I was wondering we disable web access to the expressway, either by block with internal or external firewall or directly disabling web mgmt interface, would be enough to not be exposed, while planning the upgrade to a fixed release.
Any thoughts?
Best regards
02-11-2024 10:04 PM
The Fixed release table explicitly indicates that versions prior to 14.0 require an upgrade to the fixed versions.
02-17-2024 01:52 PM
Under the first fixed releases it says after the upgrade you need issue the command "xconfiguration Security CSRFProtection status : "Enabled"" does this need to be done on the C, E, or both?
02-17-2024 02:02 PM
On both C and E.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide