CVE-2022-20814

HIGH
Published Nov 15, 2024 Modified Jul 31, 2025 CWE-295

Description

A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.  The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified Communications Manager device. An attacker could exploit this vulnerability by using a man-in-the-middle technique to intercept the traffic between the devices, and then using a self-signed certificate to impersonate the endpoint. A successful exploit could allow the attacker to view the intercepted traffic in clear text or alter the contents of the traffic. Note: Cisco Expressway-E is not affected by this vulnerability.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Is your site exposed to CVE-2022-20814?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

7.4
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Weakness Type (CWE)

CWE-295 CWE-295

Affected Products

Vendor Product
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server
cisco telepresence_video_communication_server

References

Frequently Asked Questions

What is CVE-2022-20814? +
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.  The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified Communications Manager device. An attacker could exploit this vulnerability by using a man-in-the-middle technique to intercept the traffic between the devices, and then using a self-signed certificate to impersonate the endpoint. A successful exploit could allow the attacker to view the intercepted traffic in clear text or alter the contents of the traffic. Note: Cisco Expressway-E is not affected by this vulnerability.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. It has a CVSS v3.1 base score of 7.4 (HIGH).
How severe is CVE-2022-20814? +
CVE-2022-20814 has a CVSS v3.1 score of 7.4 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2022-20814? +
CVE-2022-20814 affects products from cisco, specifically: telepresence_video_communication_server. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2022-20814? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2022-20814 — free, no signup required.