PT-2020-4946 · Cisco · Cisco Expressway

Christian Mehlmauer

·

Published

2020-11-16

·

Updated

2020-12-02

·

CVE-2020-3482

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Expressway software (affected versions not specified)
Description: A vulnerability in the Traversal Using Relays around NAT (TURN) server component could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The issue is due to improper validation of specific connection information by the TURN server within the affected software. An attacker could exploit this by sending specially crafted network traffic to the affected software, potentially allowing them to gain unauthorized network access.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05521
CVE-2020-3482

Affected Products

Cisco Expressway