Improper Certificate Validation in Expressway Series and TelePresence Video Communication Server (VCS) - CVE-2022-20814
Published: October 6, 2022
Vulnerability identifier: #VU67967
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20814
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a lack of validation of the SSL server certificate. A remote attacker can perform a man-in-the-middle (MitM) attack and view the intercepted traffic in clear text or alter the contents of the traffic.
Affected software
Expressway Series
TelePresence Video Communication Server (VCS)
TelePresence Video Communication Server (VCS)
How to mitigate CVE-2022-20814
Install updates from vendor's website.
Expressway Series - update to 14.2
TelePresence Video Communication Server (VCS) - update to 14.2
TelePresence Video Communication Server (VCS) - update to 14.2