PT-2022-2854 · Cisco · Cisco Telepresence Video Communication Server+1
Published
2022-05-18
·
Updated
2022-06-09
·
CVE-2022-20807
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Expressway Series (affected versions not specified)
Cisco TelePresence Video Communication Server (affected versions not specified)
Description
The issue is related to improper restriction of XML external entities in the software of Cisco Expressway and Cisco TelePresence Video Communication Server. This could allow a remote attacker to view the contents of arbitrary files on the server or perform network scanning of internal and external infrastructure. An authenticated, remote attacker may also be able to write files or disclose sensitive information on an affected device through the API and web-based management interfaces.
Recommendations
For Cisco Expressway Series, update to a version that addresses the issue, if available.
For Cisco TelePresence Video Communication Server, update to a version that addresses the issue, if available.
As a temporary workaround, consider restricting access to the API and web-based management interfaces until a patch is available.
Avoid using the vulnerable API endpoints until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Expressway Series
Cisco Telepresence Video Communication Server