Cisco Expressway Series and Cisco TelePresence Video Communication Server Privilege Escalation Vulnerabilities
CVE-2023-20192

7.7HIGH

Key Information:

Summary

Multiple vulnerabilities exist in Cisco Expressway Series and TelePresence Video Communication Server that could allow an authenticated attacker with Administrator-level read-only credentials to upgrade their access to Administrator with read-write permissions. Such escalations can pose significant risks to the integrity and security of the affected systems, underscoring the importance of timely patching and user credential management.

Affected Version(s)

Cisco TelePresence Video Communication Server (VCS) Expressway

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.