PT-2022-2854 · Cisco · Cisco Telepresence Video Communication Server+1

Published

2022-05-18

·

Updated

2022-06-09

·

CVE-2022-20807

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Expressway Series (affected versions not specified) Cisco TelePresence Video Communication Server (affected versions not specified)
Description The issue is related to improper restriction of XML external entities in the software of Cisco Expressway and Cisco TelePresence Video Communication Server. This could allow a remote attacker to view the contents of arbitrary files on the server or perform network scanning of internal and external infrastructure. An authenticated, remote attacker may also be able to write files or disclose sensitive information on an affected device through the API and web-based management interfaces.
Recommendations For Cisco Expressway Series, update to a version that addresses the issue, if available. For Cisco TelePresence Video Communication Server, update to a version that addresses the issue, if available. As a temporary workaround, consider restricting access to the API and web-based management interfaces until a patch is available. Avoid using the vulnerable API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03411
CVE-2022-20807

Affected Products

Cisco Expressway Series
Cisco Telepresence Video Communication Server