cbcvebase.
CVE-2023-20209
published 2023-08-16

CVE-2023-20209: A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an…

PriorityP264high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
37.89%
98.4th percentile
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to establish a remote shell with root privileges.

Affected

69 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway
ciscocisco_telepresence_video_communication_server_expressway

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted HTTP request to the web-based management interface of Cisco Expressway Series or Cisco TelePresence VCS by an authenticated attacker with read-write privileges, resulting in command injection and remote shell with root privileges.
  • Classify as CWE-94 (Code Injection); monitor web-based management interface traffic on Cisco Expressway/VCS for anomalous or crafted POST/GET requests that may carry injection payloads.
  • Restrict or monitor access to the Cisco Expressway/VCS web-based management interface; alert on authenticated sessions with read-write privileges performing unexpected command-like input patterns.
  • ·Exploitation requires an authenticated attacker with read-write privileges on the application; unauthenticated exploitation is not possible.
  • ·There are no workarounds available; remediation requires applying Cisco-released software updates.

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.