iTnews Asia
  • Home
  • News
  • Security

Cisco patches critical vulnerability in collaboration kit

Cisco patches critical vulnerability in collaboration kit

Expressway, TelePresence VCS have password reset flaw.

By Richard Chirgwin on Jun 12, 2023 10:35AM

Cisco has patched two critical-rated vulnerabilities in its Express and TelePresence products, among seven new security advisories.

According to an advisory, both Expressway and TelePresence VCS are subject to a privilege escalation bug.

One of the bugs, CVE-2023-20105, lets a remote administrator elevate their privilege from read-only to read-write.

The bug is in how the system handles password change requests.

“A successful exploit could allow the attacker to alter the passwords of any user on the system, including an administrative read-write user, and then impersonate that user,” Cisco said.

The other bug, CVE-2023-20192, is in the two systems’ privilege management.

Similarly to the first vulnerability, an attacker can elevate their read-only command line interface privileges from read-only to read-write.

“A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including modifying system configuration parameters,” Cisco said.

There is a workaround for CVE-2023-20192, which is to disable access for administrators with read-only privileges.

The list of advisories also includes three high-rated vulnerabilities in the company’s Adaptive Security Appliance Software and Firepower Threat Defense Software; Unified Communications Manager IM and Presence Service; and the AnyConnect client for Windows and Secure Client for Windows.

The Small Business 200, 300 and 500; Secure Workload; and UCM products had medium-rated vulnerabilities patched today.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
cisco cve security

Related Articles

  • Why is fragmentation the next big cybersecurity risk?
  • The maritime sector is now in the crosshairs of cybercriminals
  • Tips on how to harness AI to transform your DDoS protection into proactive cyber defence
  • Malaysia secures communications for the upcoming ASEAN Summit
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The maritime sector is now in the crosshairs of cybercriminals

The maritime sector is now in the crosshairs of cybercriminals

Why is fragmentation the next big cybersecurity risk?

Why is fragmentation the next big cybersecurity risk?

Tips on how to harness AI to transform your DDoS protection into proactive cyber defence

Tips on how to harness AI to transform your DDoS protection into proactive cyber defence

Malaysia secures communications for the upcoming ASEAN Summit

Malaysia secures communications for the upcoming ASEAN Summit

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.