Improper access control in Cisco Expressway and Cisco TelePresence Video Communication Server - CVE-2020-3482
Published: November 18, 2020 / Updated: November 19, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper validation of specific connection information by the Traversal Using Relays around NAT (TURN) server. A remote attacker can send traffic through the affected software to destinations beyond the application and gain unauthorized network access.
Affected software
Cisco TelePresence Video Communication Server
How to mitigate CVE-2020-3482
Cisco TelePresence Video Communication Server - update to X12.6.3