CVE-2023-20105
Severity
6.5MEDIUM
EPSS
0.1%
top 68.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 28
Description
A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system.
This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by authenticating to the application as a Read-only user and sending a crafted request to the web-based man…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:HExploitability: 3.1 | Impact: 5.8
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-8vgw-329g-hrw6: Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with↗2023-06-28
CVEList▶
CVE-2023-20105: A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an↗2023-06-28
📋Vendor Advisories
1Cisco▶
Cisco Expressway Series and Cisco TelePresence Video Communication Server Privilege Escalation Vulnerabilities↗2023-06-07