Improper access control in Cisco Expressway and Cisco TelePresence Video Communication Server - CVE-2020-3482

 

Improper access control in Cisco Expressway and Cisco TelePresence Video Communication Server - CVE-2020-3482

Published: November 18, 2020 / Updated: November 19, 2020


Vulnerability identifier: #VU48563
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3482
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper validation of specific connection information by the Traversal Using Relays around NAT (TURN) server. A remote attacker can send traffic through the affected software to destinations beyond the application and gain unauthorized network access.


Affected software

Cisco Expressway
Cisco TelePresence Video Communication Server

How to mitigate CVE-2020-3482

Install updates from vendor's website.

Cisco Expressway - update to X12.6.3
Cisco TelePresence Video Communication Server - update to X12.6.3

External References

Related Security Bulletins