Permissions, Privileges, and Access Controls in Expressway Series and TelePresence Video Communication Server (VCS) - CVE-2023-20192
Published: June 8, 2023
Vulnerability identifier: #VU77084
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20192
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect implementation of user role permissions. A local user can execute arbitrary commands beyond the sphere of their intended access level.
Affected software
Expressway Series
TelePresence Video Communication Server (VCS)
TelePresence Video Communication Server (VCS)
How to mitigate CVE-2023-20192
Install updates from vendor's website.
Expressway Series - update to 14.3.0
TelePresence Video Communication Server (VCS) - update to 14.3.0
TelePresence Video Communication Server (VCS) - update to 14.3.0