First published: Wed Jun 07 2023(Updated: )
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Expressway | ||
Cisco TelePresence Video Communication Server Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-expressway-priv-esc-Ls2B9t7b is high due to the potential for authenticated users to escalate their privileges.
To fix cisco-sa-expressway-priv-esc-Ls2B9t7b, upgrade the Cisco Expressway Series or Cisco TelePresence Video Communication Server to a patched version provided by Cisco.
Cisco Expressway Series and Cisco TelePresence Video Communication Server users with Administrator-level read-only credentials are affected by cisco-sa-expressway-priv-esc-Ls2B9t7b.
cisco-sa-expressway-priv-esc-Ls2B9t7b can be exploited by attackers who gain access to read-only credentials and then elevate their privileges to Administrator.
Recommended actions include applying patches provided by Cisco and reviewing user access controls to limit risk.