Improper Certificate Validation in Expressway Series and TelePresence Video Communication Server (VCS) - CVE-2022-20814

 

Improper Certificate Validation in Expressway Series and TelePresence Video Communication Server (VCS) - CVE-2022-20814

Published: October 6, 2022


Vulnerability identifier: #VU67967
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20814
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a lack of validation of the SSL server certificate. A remote attacker can perform a man-in-the-middle (MitM) attack and view the intercepted traffic in clear text or alter the contents of the traffic.


Affected software

Expressway Series
TelePresence Video Communication Server (VCS)

How to mitigate CVE-2022-20814

Install updates from vendor's website.

Expressway Series - update to 14.2
TelePresence Video Communication Server (VCS) - update to 14.2

External References

Related Security Bulletins