CVE-2022-20814
published 2024-11-15CVE-2022-20814: A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain…
PriorityP352high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.90%
55.6th percentile
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified Communications Manager device. An attacker could exploit this vulnerability by using a man-in-the-middle technique to intercept the traffic between the devices, and then using a self-signed certificate to impersonate the endpoint. A successful exploit could allow the attacker to view the intercepted traffic in clear text or alter the contents of the traffic.
Note: Cisco Expressway-E is not affected by this vulnerability.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected
121 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
| cisco | cisco_telepresence_video_communication_server_expressway | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
vendor_cisco·2022-10-05·CVSS 7.4
CVE-2022-20814 [HIGH] CWE-295 Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow a remote attacker to bypass certificate validation or conduct cross-site request forgery attacks on an affected device.
Note: Cisco Expressway Series refers to the Expressway Control (Expressway-C) device and the Expressway Edge (Expressway-E) device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the followi
Cisco
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20814 Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
CVE-2022-20814: Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow a remote attacker to bypass certificate validation or conduct cross-site request forgery attacks on an affected device. Note: Cisco Expressway Series refers to the Expressway Control (Expressway-C) device and the Expressway Edge (Expressway-E) device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-295, CWE-352, CWE-295, CWE-352
Bug IDs: CSCwa25097, CSCwa25108, CSCwa25108, CSCwa25097, CSCwa25097
GHSA
GHSA-rg5m-fc62-h68h: A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain
ghsa_unreviewed·2024-11-15
CVE-2022-20814 [HIGH] CWE-295 GHSA-rg5m-fc62-h68h: A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified Communications Manager device. An attacker could exploit this vulnerability by using a man-in-the-middle technique to intercept the traffic between the devices, and then using a self-signed certificate to impersonate the endpoint. A successful exploit could allow the attacker to view the intercepted traffic in clear text or alter the contents of the traffic.
Note: Cisco Expressway-E is not affected by this vulnerability.Cisco has released sof
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-csrf-sqpsSfY6https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-bng-Gmg5Gxthttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ncs4k-tl1-GNnLwC6https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xr-cdp-wnALzvT2
2024-11-15
Published