PT-2020-1388 · Cisco · Cisco Roomos+2

Published

2020-01-22

·

Updated

2020-10-05

·

CVE-2020-3143

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco TelePresence Collaboration Endpoint (CE) Software (affected versions not specified) Cisco TelePresence Codec (TC) Software (affected versions not specified) Cisco RoomOS Software (affected versions not specified)
Description A vulnerability in the video endpoint API (xAPI) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The issue is due to insufficient validation of user-supplied input to the xAPI. An attacker could exploit this by sending a crafted request to the xAPI, potentially allowing them to read and write arbitrary files in the system. To exploit this, an attacker would need either an In-Room Control or administrator account.
Recommendations For Cisco TelePresence Collaboration Endpoint (CE) Software, update to a version that includes the fix for this issue. For Cisco TelePresence Codec (TC) Software, update to a version that includes the fix for this issue. For Cisco RoomOS Software, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the xAPI to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00339
CVE-2020-3143

Affected Products

Cisco Roomos
Cisco Telepresence Codec (Tc)
Cisco Telepresence Collaboration Endpoint (Ce)