7.4
CVE-2022-20814
- EPSS 0.17%
- Published 15.11.2024 16:15:22
- Last modified 31.07.2025 15:44:19
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified Communications Manager device. An attacker could exploit this vulnerability by using a man-in-the-middle technique to intercept the traffic between the devices, and then using a self-signed certificate to impersonate the endpoint. A successful exploit could allow the attacker to view the intercepted traffic in clear text or alter the contents of the traffic. Note: Cisco Expressway-E is not affected by this vulnerability.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Telepresence Video Communication Server Versionx8.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.1.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.1.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.2.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.2.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.5 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.5.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.5.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.5.3 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.6 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.6.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.7 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.7.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.7.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.7.3 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.8 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.8.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.8.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.8.3 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.9 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.9.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.9.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.10.0 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.10.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.10.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.10.3 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.10.4 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.11.0 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.11.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.11.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.11.3 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx8.11.4 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.5.0 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.5.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.5.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.5.3 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.5.4 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.5.5 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.5.6 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.5.7 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.5.8 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.5.9 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.6.0 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.6.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.6.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.6.3 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.6.4 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.7.0 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx12.7.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx14.0.0 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx14.0.1 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx14.0.2 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx14.0.3 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx14.0.4 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx14.0.5 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx14.0.6 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx14.0.7 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx14.0.8 SwEditionexpressway
Cisco ≫ Telepresence Video Communication Server Versionx14.0.9 SwEditionexpressway
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.17% | 0.383 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@cisco.com | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.