PT-2020-4946 · Cisco · Cisco Expressway
Christian Mehlmauer
·
Published
2020-11-16
·
Updated
2020-12-02
·
CVE-2020-3482
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Expressway software (affected versions not specified)
Description:
A vulnerability in the Traversal Using Relays around NAT (TURN) server component could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The issue is due to improper validation of specific connection information by the TURN server within the affected software. An attacker could exploit this by sending specially crafted network traffic to the affected software, potentially allowing them to gain unauthorized network access.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Expressway