Improper Neutralization of Null Byte or NUL Character in Expressway Series and Cisco TelePresence Video Communication Server - CVE-2022-20813
Published: July 7, 2022
Vulnerability identifier: #VU64963
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20813
CWE-ID: CWE-158
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper certificate validation. A remote attacker can perform a man-in-the-middle attack and view the intercepted traffic in clear text or alter the contents of the traffic.
Affected software
Expressway Series
Cisco TelePresence Video Communication Server
Cisco TelePresence Video Communication Server
How to mitigate CVE-2022-20813
Install updates from vendor's website.
Expressway Series - update to 14.0.7
Cisco TelePresence Video Communication Server - update to 14.0.7
Cisco TelePresence Video Communication Server - update to 14.0.7