PT-2020-2867 · Cisco · Cisco Roomos+1

Published

2020-06-17

·

Updated

2020-06-24

·

CVE-2020-3336

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software (affected versions not specified)
Description A vulnerability in the software upgrade process could allow an authenticated, remote attacker to modify the filesystem, causing a denial of service (DoS) or gaining privileged access to the root filesystem. This issue is due to insufficient input validation. An attacker with administrative privileges could exploit this by sending requests with malformed parameters to the system using the console, Secure Shell (SSH), or web API. A successful exploit could allow the attacker to modify the device configuration or cause a DoS.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03021
CVE-2020-3336

Affected Products

Cisco Roomos
Cisco Telepresence Collaboration Endpoint