Vulnerabilities > Cisco > Expressway > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-07-06 CVE-2022-20812 Path Traversal vulnerability in Cisco Telepresence Video Communication Server
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device.
network
low complexity
cisco CWE-22
6.5
2022-07-06 CVE-2022-20813 Improper Certificate Validation vulnerability in Cisco Telepresence Video Communication Server
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device.
network
high complexity
cisco CWE-295
5.9
2020-11-18 CVE-2020-3482 Improper Privilege Management vulnerability in Cisco products
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations.
network
low complexity
cisco CWE-269
6.5
2017-10-19 CVE-2017-12287 Improper Input Validation vulnerability in Cisco products
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system to restart unexpectedly, resulting in a temporary denial of service (DoS) condition.
network
low complexity
cisco CWE-20
4.3
2016-12-14 CVE-2016-9207 7PK - Security Features vulnerability in Cisco Expressway X8.7.2/X8.8.3
A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts.
network
low complexity
cisco CWE-254
6.5