QID 38865

Date Published: 2022-05-24

QID 38865: Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities (cisco-sa-expressway-filewrite-bsFVwueV)

Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device.

Affected Products
Cisco Expressway Series and Cisco TelePresence VCS prior to version 14.0.7

QID Detection Logic (Unauthenticated):
The check matches version of Cisco TelePresence Video Communication Server Expressway on the exposed banner information under the SIP banner.

A successful exploit could allow the attacker to read arbitrary files on the underlying operating system at a rate that impacts system performance.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-expressway-filewrite-bsFVwueV for more information.

    CVEs related to QID 38865

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-expressway-filewrite-bsFVwueV URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-bsFVwueV