Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hqc2-r8jq-7rg7

Опубликовано: 28 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details section of this advisory.

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS

Процентиль: 43%
0.00206
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.6
nvd
больше 2 лет назад

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 8.4
fstec
больше 2 лет назад

Уязвимость интерфейса командной строки (CLI) микропрограммного обеспечения шлюза Cisco Expressway и микропрограммного обеспечения устройства управления вызовами Cisco TelePresence Video Communication Server (VCS), позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 43%
0.00206
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-20