Medium severity5.0NVD Advisory· Published Feb 7, 2019· Updated Jun 17, 2026
CVE-2019-1679
CVE-2019-1679
Description
A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host. This type of attack is commonly referred to as server-side request forgery (SSRF). The vulnerability is due to insufficient access controls for the REST API of Cisco Expressway Series and Cisco TelePresence VCS. An attacker could exploit this vulnerability by submitting a crafted HTTP request to the affected server. Versions prior to XC4.3.4 are affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:cisco:telepresence_conductor:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cisco:telepresence_conductor:*:*:*:*:*:*:*:*range: <xc4.3.4
- (no CPE)range: <XC4.3.4
- (no CPE)range: unspecified
cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:*:*:*:*range: <x12.5
- (no CPE)range: <XC4.3.4
- (no CPE)range: unspecified
- Range: <XC4.3.4
- Range: unspecified
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/106940nvdBroken LinkThird Party AdvisoryVDB Entry
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190206-rest-api-ssrfnvdVendor Advisory
News mentions
0No linked articles in our index yet.