PT-2021-2988 · Cisco · Cisco Telepresence Collaboration Endpoint (Ce)+1

Published

2021-05-05

·

Updated

2021-05-14

·

CVE-2021-1532

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco TelePresence Collaboration Endpoint (CE) Software (affected versions not specified) Cisco RoomOS Software (affected versions not specified)
Description A vulnerability in the video endpoint API (xAPI) could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system due to insufficient path validation of command arguments. An attacker could exploit this by sending a crafted command request to the xAPI, potentially allowing them to read the contents of any file on the device filesystem.
Recommendations For Cisco TelePresence Collaboration Endpoint (CE) Software, consider restricting access to the xAPI until a fix is available. For Cisco RoomOS Software, consider disabling the xAPI functionality as a temporary workaround until a patch is available. Restrict access to sensitive files on the device filesystem to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02576
CVE-2021-1532

Affected Products

Cisco Roomos
Cisco Telepresence Collaboration Endpoint (Ce)