CVE-2023-20105 is a privilege escalation vulnerability in the change password functionality of Cisco Expressway Series and TelePresence Video Communication Server (VCS). An authenticated, remote attacker with Read-only credentials can exploit this flaw by sending a crafted request to the web-based management interface. Successful exploitation allows the attacker to alter any user's password, including administrative accounts, thereby gaining Administrator privileges. This vulnerability has a CVSS score of 6.5 (Medium) and is rated as a FAUCET Risk Score of 35/100. The attack vector is network-based with low attack complexity, requiring only low privileges and no user interaction, leading to a high impact on integrity. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. While there has been some community discussion and media coverage, it is not considered a "Hot List" CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= x14.0.3CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:expressway:*:*:* | ||
<= x14.0.3CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.