iTnews Asia
  • Home
  • News
  • Security

Cisco patches critical vulnerability in collaboration kit

Cisco patches critical vulnerability in collaboration kit

Expressway, TelePresence VCS have password reset flaw.

By Richard Chirgwin on Jun 12, 2023 10:35AM

Cisco has patched two critical-rated vulnerabilities in its Express and TelePresence products, among seven new security advisories.

According to an advisory, both Expressway and TelePresence VCS are subject to a privilege escalation bug.

One of the bugs, CVE-2023-20105, lets a remote administrator elevate their privilege from read-only to read-write.

The bug is in how the system handles password change requests.

“A successful exploit could allow the attacker to alter the passwords of any user on the system, including an administrative read-write user, and then impersonate that user,” Cisco said.

The other bug, CVE-2023-20192, is in the two systems’ privilege management.

Similarly to the first vulnerability, an attacker can elevate their read-only command line interface privileges from read-only to read-write.

“A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including modifying system configuration parameters,” Cisco said.

There is a workaround for CVE-2023-20192, which is to disable access for administrators with read-only privileges.

The list of advisories also includes three high-rated vulnerabilities in the company’s Adaptive Security Appliance Software and Firepower Threat Defense Software; Unified Communications Manager IM and Presence Service; and the AnyConnect client for Windows and Secure Client for Windows.

The Small Business 200, 300 and 500; Secure Workload; and UCM products had medium-rated vulnerabilities patched today.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cisco cve security

Related Articles

  • Sophos: Identity attacks have overtaken software flaws as entry point of ransomware
  • Strategies to mitigate against the real world impact of identity attacks
  • How can the Agentic AI workspace remain secure for APAC organisations?
  • AI-fuelled attacks forcing enterprises to rethink security architecture
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

How can the Agentic AI workspace remain secure for APAC organisations?

How can the Agentic AI workspace remain secure for APAC organisations?

Strategies to mitigate against the real world impact of identity attacks

Strategies to mitigate against the real world impact of identity attacks

Sophos: Identity attacks have overtaken software flaws as entry point of ransomware

Sophos: Identity attacks have overtaken software flaws as entry point of ransomware

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.