PT-2023-3112 · Cisco · Cisco Expressway Series+1

CVE-2023-20192

·

Publicado

2023-06-07

·

Atualizado

2023-07-06

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Expressway Series versions (affected versions not specified) Cisco TelePresence Video Communication Server (VCS) versions (affected versions not specified)
Description The issue is related to insufficient role-based access control in the CLI interface of the Cisco Expressway and Cisco TelePresence Video Communication Server (VCS) software. This could allow an attacker to elevate their privileges. An authenticated attacker with Administrator-level read-only credentials may be able to gain Administrator with read-write credentials on an affected system.
Recommendations For Cisco Expressway Series, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Cisco TelePresence Video Communication Server (VCS), at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03206
CVE-2023-20192

Produtos afetados

Cisco Expressway Series
Cisco Telepresence Video Communication Server