QID 38875
Date Published: 2022-07-07
QID 38875: Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities (cisco-sa-expressway-overwrite-3buqW8LH)
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device.
Affected Products
Cisco Expressway Series and Cisco TelePresence VCS prior to version 14.0.7
QID Detection Logic (Unauthenticated):
The check matches version of Cisco TelePresence Video Communication Server Expressway on the exposed banner information under the SIP banner.
Successful exploit could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device.
Customers are advised to refer to cisco-sa-expressway-overwrite-3buqW8LH for more information.
- cisco-sa-expressway-overwrite-3buqW8LH -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-overwrite-3buqW8LH
CVEs related to QID 38875
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-expressway-overwrite-3buqW8LH |
|