PT-2020-4959 · Cisco · Cisco Roomos+1

Published

2020-11-18

·

Updated

2020-11-25

·

CVE-2020-26068

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Telepresence CE Software (affected versions not specified) Cisco RoomOS Software (affected versions not specified)
Description A vulnerability in the xAPI service could allow an authenticated, remote attacker to generate an access token for an affected device due to insufficient access authorization. An attacker could exploit this vulnerability by using the xAPI service to generate a specific token, potentially allowing them to enable experimental features on the device that should not be available to users.
Recommendations For Cisco Telepresence CE Software, consider disabling the xAPI service until a patch is available to prevent exploitation. For Cisco RoomOS Software, restrict access to the xAPI service to minimize the risk of exploitation. As a temporary workaround, consider disabling any features that rely on the generated access token until a patch is available.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05534
CVE-2020-26068

Affected Products

Cisco Roomos
Cisco Telepresence Ce