CVE-2022-20809

Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:expressway:*:*:*

History

07 Jun 2022, 16:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 6.5
CWE CWE-532
First Time Cisco
Cisco telepresence Video Communication Server
CPE cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:expressway:*:*:*
References (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-bsFVwueV - (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-bsFVwueV - Vendor Advisory

26 May 2022, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-26 14:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-20809

Mitre link : CVE-2022-20809

CVE.ORG link : CVE-2022-20809


JSON object : View

Products Affected

cisco

  • telepresence_video_communication_server
CWE
CWE-532

Insertion of Sensitive Information into Log File