Unverified Password Change in Expressway Series and TelePresence Video Communication Server (VCS) - CVE-2023-20105

 

Unverified Password Change in Expressway Series and TelePresence Video Communication Server (VCS) - CVE-2023-20105

Published: June 8, 2023


Vulnerability identifier: #VU77083
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20105
CWE-ID: CWE-620
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to incorrect handling of password change requests in the change password functionality. A remote user can send a specially crafted request and alter the passwords of any user on the system and then impersonate that user.


Affected software

Expressway Series
TelePresence Video Communication Server (VCS)

How to mitigate CVE-2023-20105

Install updates from vendor's website.

Expressway Series - update to 14.2.1
TelePresence Video Communication Server (VCS) - update to 14.2.1

External References

Related Security Bulletins