Unverified Password Change in Expressway Series and TelePresence Video Communication Server (VCS) - CVE-2023-20105
Published: June 8, 2023
Vulnerability identifier: #VU77083
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20105
CWE-ID: CWE-620
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to incorrect handling of password change requests in the change password functionality. A remote user can send a specially crafted request and alter the passwords of any user on the system and then impersonate that user.
Affected software
Expressway Series
TelePresence Video Communication Server (VCS)
TelePresence Video Communication Server (VCS)
How to mitigate CVE-2023-20105
Install updates from vendor's website.
Expressway Series - update to 14.2.1
TelePresence Video Communication Server (VCS) - update to 14.2.1
TelePresence Video Communication Server (VCS) - update to 14.2.1