iTnews Asia
  • Home
  • News
  • Security

Cisco patches critical vulnerability in collaboration kit

Cisco patches critical vulnerability in collaboration kit

Expressway, TelePresence VCS have password reset flaw.

By Richard Chirgwin on Jun 12, 2023 10:35AM

Cisco has patched two critical-rated vulnerabilities in its Express and TelePresence products, among seven new security advisories.

According to an advisory, both Expressway and TelePresence VCS are subject to a privilege escalation bug.

One of the bugs, CVE-2023-20105, lets a remote administrator elevate their privilege from read-only to read-write.

The bug is in how the system handles password change requests.

“A successful exploit could allow the attacker to alter the passwords of any user on the system, including an administrative read-write user, and then impersonate that user,” Cisco said.

The other bug, CVE-2023-20192, is in the two systems’ privilege management.

Similarly to the first vulnerability, an attacker can elevate their read-only command line interface privileges from read-only to read-write.

“A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including modifying system configuration parameters,” Cisco said.

There is a workaround for CVE-2023-20192, which is to disable access for administrators with read-only privileges.

The list of advisories also includes three high-rated vulnerabilities in the company’s Adaptive Security Appliance Software and Firepower Threat Defense Software; Unified Communications Manager IM and Presence Service; and the AnyConnect client for Windows and Secure Client for Windows.

The Small Business 200, 300 and 500; Secure Workload; and UCM products had medium-rated vulnerabilities patched today.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cisco cve security

Related Articles

  • Qantas hit by cyberattack, data of six million customers exposed
  • Your organisation’s physical security can be a gateway for cybercriminals
  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Qantas hit by cyberattack, data of six million customers exposed

Qantas hit by cyberattack, data of six million customers exposed

Your organisation’s physical security can be a gateway for cybercriminals

Your organisation’s physical security can be a gateway for cybercriminals

Cyber criminals in Malaysia are posing as Lazada agents

Cyber criminals in Malaysia are posing as Lazada agents

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.