Inclusion of Sensitive Information in Log Files in Cisco Expressway and Cisco TelePresence Video Communication Server - CVE-2022-20809
Published: May 19, 2022
Vulnerability identifier: #VU63424
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20809
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files in the logging component. A remote user can read the log files and gain access to sensitive data.
Affected software
Cisco Expressway
Cisco TelePresence Video Communication Server
Cisco TelePresence Video Communication Server
How to mitigate CVE-2022-20809
Install updates from vendor's website.
Cisco Expressway - update to 14.0.7
Cisco TelePresence Video Communication Server - update to 14.0.7
Cisco TelePresence Video Communication Server - update to 14.0.7