Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Description
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated remote attackers can write arbitrary files or disclose sensitive information via the API and web interfaces of Cisco Expressway Series and TelePresence VCS.
Vulnerability
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. The affected products include all Cisco Expressway Series and Cisco TelePresence VCS releases prior to the fixed versions. The default configuration is vulnerable for CVE-2022-20806 and CVE-2022-20807. These vulnerabilities are not dependent on one another [1].
Exploitation
An attacker must have authenticated access to the affected device's API or web-based management interface. No additional privileges or user interaction beyond authentication is required to trigger the vulnerable code path. The specific attack vectors involve crafted requests to the cluster database API or other management endpoints, but the exact sequence of steps is not publicly detailed beyond the advisory [1].
Impact
Successful exploitation could allow an attacker to write arbitrary files to the device's filesystem or disclose sensitive information. The impact varies depending on the specific vulnerability: CVE-2022-20806 enables arbitrary file write, while CVE-2022-20807 enables information disclosure. The attacker could gain access to sensitive configuration data or overwrite critical system files, potentially leading to further compromise [1].
Mitigation
Cisco has released software updates that address these vulnerabilities. The fixed versions are available for Cisco Expressway Series and Cisco TelePresence VCS. There are no workarounds that address these vulnerabilities. Administrators should upgrade to the appropriate patched release as specified in the Cisco Security Advisory [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: n/a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-bsFVwueVmitrevendor-advisoryx_refsource_CISCO
News mentions
0No linked articles in our index yet.