CVE-2023-20209

MEDIUM

Cisco Expressway Series/VCS - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-20209. PoCs published by peter5he1by.

AI-analyzed exploit summary This PoC exploits CVE-2023-20209, a post-authentication command injection vulnerability in Cisco Expressway's CRL updater functionality. It leverages a reverse shell payload injected via the distribution_points parameter after authenticating as an administrator.

Description

A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to establish a remote shell with root privileges.

Exploits (1)

nomisec WORKING POC
by peter5he1by · poc
https://github.com/peter5he1by/CVE-2023-20209

This PoC exploits CVE-2023-20209, a post-authentication command injection vulnerability in Cisco Expressway's CRL updater functionality. It leverages a reverse shell payload injected via the distribution_points parameter after authenticating as an administrator.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cisco Expressway (versions affected by CVE-2023-20209)
Auth required
Prerequisites: Valid administrator credentials · Network access to the target · Python 3 environment
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 6.5
EPSS 0.3427
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94 CWE-77
Status published
Products (1)
cisco/telepresence_video_communication_server < 14.3.1 (2 CPE variants)
Published Aug 16, 2023
Tracked Since Feb 18, 2026