CVE-2023-20209

Severity
7.2HIGH
EPSS
31.9%
top 3.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16

Description

A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 1.2 | Impact: 5.2

🔴Vulnerability Details

2
CVEList
CVE-2023-20209: A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a2023-08-16
GHSA
GHSA-fqmx-hq6j-36x9: A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a2023-08-16

📋Vendor Advisories

1
Cisco
Cisco Expressway Series and Cisco TelePresence Video Communication Server Command Injection Vulnerability2023-08-16
CVE-2023-20209 (HIGH CVSS 7.2) | A vulnerability in the web-based ma | cvebase.io