Vulnerabilities > Cisco > Expressway > x8.2.2

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44487 Resource Exhaustion vulnerability in multiple products
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5
2022-07-06 CVE-2022-20812 Path Traversal vulnerability in Cisco Telepresence Video Communication Server
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device.
network
low complexity
cisco CWE-22
6.5
2022-07-06 CVE-2022-20813 Improper Certificate Validation vulnerability in Cisco Telepresence Video Communication Server
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device.
network
high complexity
cisco CWE-295
5.9
2021-08-18 CVE-2021-34715 Improper Verification of Cryptographic Signature vulnerability in Cisco products
A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system.
network
low complexity
cisco CWE-347
7.2
2020-11-18 CVE-2020-3482 Improper Privilege Management vulnerability in Cisco products
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations.
network
low complexity
cisco CWE-269
6.4
2020-10-08 CVE-2020-3596 Always-Incorrect Control Flow Implementation vulnerability in Cisco products
A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-670
7.5
2017-02-01 CVE-2017-3790 Improper Input Validation vulnerability in Cisco products
A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.8