← Back to feed
Vulnerabilities & PatchesEmerging1 sourceMar 9, 2022 · 18:16via API Security News

Issue 175: Vulnerabilities affecting Cisco platforms, GitLab instances, and campus access control

Brief

This week, we have three vulnerabilities: the first in the Cisco Expressway Series and TelePresence video communications service, another vulnerability in self-managed GitLab instances, and a bug affecting a campus access control system. On top of this, we also have views on privacy concerns for APIs.

Vulnerability: Patches for critical issues in Cisco video communications services

This week, Cisco has disclosed two critical flaws affecting their Expressway Series and TelePresence video communications service. The issues are tracked as CVE-2022-20754 and CVE-2022-20755 , both scoring high on CVSS at 9.

  • The first vulnerability allowed an authenticated user with read/write access to perform path traversal attacks using the cluster database API. An attacker could use this vulnerability to overwrite arbitrary files on the operating system potentially leading to device takeover.
Read more on API Security News