CVE-2022-20812 describes multiple vulnerabilities in the API and web-based management interface of Cisco Expressway Series and TelePresence Video Communication Server (VCS), allowing remote attackers to overwrite arbitrary files or conduct null byte poisoning. With a CVSS score of 6.5 (MEDIUM), this vulnerability requires high privileges (PR:H) but has low attack complexity (AC:L) and network access (AV:N), potentially leading to high impact on integrity and availability (I:H, A:H). While there is no known active exploitation (KEV: No) or public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community attention with 3 mentions and 3 media articles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< x14.0.7CPE matchmatch criteria | cpe:2.3:a:cisco:expressway:*:*:*:*:*:*:*:* | ||
< x14.0.7CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.