iTnews Asia
  • Home
  • News
  • Security

Cisco completes fix for critical Telepresence server bug

Cisco completes fix for critical Telepresence server bug

Coming "late April".

By Richard Chirgwin on Apr 10, 2023 11:21AM

Cisco has shipped fixed software for a critical bug in its Expressway Series and TelePresence Video Communication Server (VCS) products, nine months after being first disclosed.

The bugs, in the APIs and web-based management consoles of the two products, were partially fixed last July.

CVE-2022-20812 is the API bug which allowed an authenticated remote administrator to overwrite operating system files as root.

CVE-2022-20813 allowed an unauthenticated remote man-in-the-middle attack to intercept traffic between devices, and then use a crafted certificate to impersonate an endpoint.

“A successful exploit could allow the attacker to view the intercepted traffic in clear text or alter the contents of the traffic”, Cisco’s advisory said.

That advisory has been updated to advise customers that version 14.0.7 of the software, released last July, provided “a partial fix” to the problem.

“For complete coverage, customers should upgrade to Release 14.3 or higher,” the advisory stated, adding that the fully patched version will ship later this month.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cisco security security vulnerability

Related Articles

  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
  • Cybersecurity threats CISOs should be most worried about in 2025
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The best way to outsmart your threat actors is to think like one

The best way to outsmart your threat actors is to think like one

What are the most pressing cyber security concerns going into 2025?

What are the most pressing cyber security concerns going into 2025?

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

How cybercriminals are exploiting LLMs to harm your business

How cybercriminals are exploiting LLMs to harm your business

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.