Severity
6.5MEDIUM
EPSS
0.1%
top 68.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 28

Description

A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by authenticating to the application as a Read-only user and sending a crafted request to the web-based man

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:HExploitability: 3.1 | Impact: 5.8

🔴Vulnerability Details

2
GHSA
GHSA-8vgw-329g-hrw6: Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with2023-06-28
CVEList
CVE-2023-20105: A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an2023-06-28

📋Vendor Advisories

1
Cisco
Cisco Expressway Series and Cisco TelePresence Video Communication Server Privilege Escalation Vulnerabilities2023-06-07
CVE-2023-20105 (MEDIUM CVSS 6.5) | A vulnerability in the change passw | cvebase.io