PT-2022-3468 · Cisco · Cisco Telepresence Video Communication Server+1

Jason Crowder

·

Published

2022-07-06

·

Updated

2023-04-07

·

CVE-2022-20812

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the API and the web-based management interface of the affected devices. These vulnerabilities could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. The vulnerability is also associated with insufficient validation of user-input arguments, which could enable a remote attacker to bypass absolute path restrictions and overwrite files in the underlying operating system with root privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-04247
CVE-2022-20812

Affected Products

Cisco Expressway Series
Cisco Telepresence Video Communication Server