Cisco Telepresence Video Communication Server Expressway vulnerabilities

23 known vulnerabilities affecting cisco/cisco_telepresence_video_communication_server_expressway.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM10

Vulnerabilities

Page 1 of 2
CVE-2025-20179MEDIUMCVSS 6.1vX8.11.2vX8.6+79 more2025-02-05
CVE-2025-20179 [MEDIUM] CWE-79 CVE-2025-20179: A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unau A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit
cvelistv5nvd
CVE-2022-20853HIGHCVSS 7.4vX8.11.2vX8.6+57 more2024-11-15
CVE-2022-20853 [HIGH] CWE-352 CVE-2022-20853: A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS coul A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system. An attacker could ex
cvelistv5nvd
CVE-2022-20814HIGHCVSS 7.4vX8.11.2vX8.6+58 more2024-11-15
CVE-2022-20814 [HIGH] CWE-295 CVE-2022-20814: A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified
cvelistv5nvd
CVE-2024-20492MEDIUMCVSS 6.7vX8.11.2vX8.6+77 more2024-10-02
CVE-2024-20492 [MEDIUM] CWE-77 CVE-2024-20492: A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, loc A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have Administrator-level credentials with read-write privileges on an affected device.
cvelistv5nvd
CVE-2024-20497MEDIUMCVSS 4.3vX8.11.2vX8.6+76 more2024-09-04
CVE-2024-20497 [MEDIUM] CWE-285 CVE-2024-20497: A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacke A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is due to inadequate authorization checks for Mobile and Remote Access (MRA) users. An attacker could exploit this vulnerability by running a series of crafted commands. A succ
cvelistv5nvd
CVE-2024-20400MEDIUMCVSS 4.7vX8.5.1vX8.5.3+72 more2024-07-17
CVE-2024-20400 [MEDIUM] CWE-601 CVE-2024-20400: A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unau A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from
cvelistv5nvd
CVE-2024-20255HIGHCVSS 7.1vX8.5.1vX8.5.3+67 more2024-02-07
CVE-2024-20255 [HIGH] CWE-352 CVE-2024-20255: A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communicatio A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system
cvelistv5nvd
CVE-2024-20254HIGHCVSS 8.8vX8.5.1vX8.5.3+67 more2024-02-07
CVE-2024-20254 [HIGH] CWE-352 CVE-2024-20254: Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Serve Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices
cvelistv5nvd
CVE-2024-20252HIGHCVSS 8.8vX8.5.1vX8.5.3+67 more2024-02-07
CVE-2024-20252 [HIGH] CWE-352 CVE-2024-20252: Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Serve Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices
cvelistv5nvd
CVE-2023-20209HIGHCVSS 7.2vX8.5.1vX8.5.3+65 more2023-08-16
CVE-2023-20209 [HIGH] CWE-94 CVE-2023-20209: A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePrese A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device. This vulnerability is
cvelistv5nvd
CVE-2023-20192HIGHCVSS 7.7vn/a2023-06-28
CVE-2023-20192 [HIGH] CWE-20 CVE-2023-20192: Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Serve Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway Series" refers to Cisco Expressway Contro
cvelistv5nvd
CVE-2023-20105MEDIUMCVSS 6.5vX8.5.1vX8.5.3+60 more2023-06-28
CVE-2023-20105 [MEDIUM] CWE-20 CVE-2023-20105: A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresen A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system. This vulnerability is due to incorrect handling of password change requests. An a
cvelistv5nvd
CVE-2022-20812MEDIUMCVSS 6.5vn/a2022-07-06
CVE-2022-20812 [MEDIUM] CWE-158 CVE-2022-20812: Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Se Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers to the Expressway Control (Expre
cvelistv5nvd
CVE-2022-20813MEDIUMCVSS 5.9vn/a2022-07-06
CVE-2022-20813 [MEDIUM] CWE-158 CVE-2022-20813: Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Se Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers to the Expressway Control (Expre
cvelistv5nvd
CVE-2022-20806HIGHCVSS 7.1vn/a2022-05-27
CVE-2022-20806 [HIGH] CWE-532 CVE-2022-20806: Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series a Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of thi
cvelistv5nvd
CVE-2022-20807MEDIUMCVSS 6.5vn/a2022-05-27
CVE-2022-20807 [MEDIUM] CWE-532 CVE-2022-20807: Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series a Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of t
cvelistv5nvd
CVE-2022-20809MEDIUMCVSS 6.5vn/a2022-05-26
CVE-2022-20809 [MEDIUM] CWE-532 CVE-2022-20809: Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series a Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of t
cvelistv5nvd
CVE-2022-20755HIGHCVSS 7.2vn/a2022-04-06
CVE-2022-20755 [HIGH] CWE-23 CVE-2022-20755: Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series a Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the ro
cvelistv5nvd
CVE-2022-20754HIGHCVSS 7.2vn/a2022-04-06
CVE-2022-20754 [HIGH] CWE-23 CVE-2022-20754: Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series a Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the ro
cvelistv5nvd
CVE-2021-34716HIGHCVSS 7.2vn/a2021-08-18
CVE-2021-34716 [HIGH] CWE-460 CVE-2021-34716: A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePrese A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the root user. This vulnerability is due to incorrect handling of certain crafted software images that are
cvelistv5nvd