CVE-2022-20814

HIGH

Cisco TelePresence Video Communication Server - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.  The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified Communications Manager device. An attacker could exploit this vulnerability by using a man-in-the-middle technique to intercept the traffic between the devices, and then using a self-signed certificate to impersonate the endpoint. A successful exploit could allow the attacker to view the intercepted traffic in clear text or alter the contents of the traffic. Note: Cisco Expressway-E is not affected by this vulnerability.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Scores

CVSS v3 7.4
EPSS 0.0012
EPSS Percentile 31.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (50)
cisco/telepresence_video_communication_server x8.1
cisco/telepresence_video_communication_server x8.1.1
cisco/telepresence_video_communication_server x8.1.2
cisco/telepresence_video_communication_server x8.2
cisco/telepresence_video_communication_server x8.2.1
cisco/telepresence_video_communication_server x8.2.2
cisco/telepresence_video_communication_server x8.5
cisco/telepresence_video_communication_server x8.5.1
cisco/telepresence_video_communication_server x8.5.2
cisco/telepresence_video_communication_server x8.5.3
... and 40 more
Published Nov 15, 2024
Tracked Since Feb 18, 2026