CVE-2023-20209: medium-severity vulnerability in Cisco TelePresence Video Communication Server…
Published · Updated
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 41%
exploitation probability
41%top 1% of all CVEs
observed exploitation
nono source reports it
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to establish a remote shell with root privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Related CVEs — Cisco TelePresence Video Communication Server…
In the same product, most dangerous first.
CVE-2022-20755CRITICALCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 3.3%CVE-2022-20754CRITICALCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 3.3%CVE-2021-34716MEDIUMCisco Expressway Series and TelePresence Video Communication Server Remote Code Execution VulnerabilityEPSS 2.4%CVE-2022-20812CRITICALCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 1.9%CVE-2020-3482MEDIUMCisco Expressway Software Unauthorized Access Information Disclosure VulnerabilityEPSS 1.4%CVE-2020-3596MEDIUMCisco Expressway Series and TelePresence Video Communication Server Denial of Service VulnerabilityEPSS 1.2%