CVE-2023-20209: fallo de gravedad media en Cisco TelePresence Video Communication Server…
Publicada el · Actualizada el
25Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.5epss 41%
probabilidad de explotación
41%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to establish a remote shell with root privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Productos afectados
Cisco · Cisco TelePresence Video Communication Server (VCS) ExpresswayCVEs relacionadas — Cisco TelePresence Video Communication Server…
En el mismo producto, de las más peligrosas a las menos.
CVE-2022-20755CRITICALCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 3.3%CVE-2022-20754CRITICALCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 3.3%CVE-2021-34716MEDIUMCisco Expressway Series and TelePresence Video Communication Server Remote Code Execution VulnerabilityEPSS 2.4%CVE-2022-20812CRITICALCisco Expressway Series and Cisco TelePresence Video Communication Server VulnerabilitiesEPSS 1.9%CVE-2020-3482MEDIUMCisco Expressway Software Unauthorized Access Information Disclosure VulnerabilityEPSS 1.4%CVE-2020-3596MEDIUMCisco Expressway Series and TelePresence Video Communication Server Denial of Service VulnerabilityEPSS 1.2%