Severity
7.4HIGH
EPSS
0.1%
top 68.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified Communications Manager device. An attacker could exploit this vulnerability by using a man-in-the-middle technique to intercept the traffic betwee

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

🔴Vulnerability Details

2
CVEList
Cisco Expressway Series and Cisco TelePresence VCS Improper Certificate Validation Vulnerability2024-11-15
GHSA
GHSA-rg5m-fc62-h68h: A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain2024-11-15

📋Vendor Advisories

1
Cisco
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities2022-10-05
CVE-2022-20814 (HIGH CVSS 7.4) | A vulnerability in the certificate | cvebase.io