PT-2022-5342 · Cisco · Cisco Roomos+1
Jason Crowder
·
Published
2022-10-19
·
Updated
2022-10-31
·
CVE-2022-20955
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco TelePresence Collaboration Endpoint (CE) Software (affected versions not specified)
Cisco RoomOS Software (affected versions not specified)
Description
The issue is related to inadequate access control in the command-line interface (CLI) of the Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS, allowing an attacker to overwrite arbitrary files. This could also enable path traversal attacks, allowing the viewing of sensitive data or writing of arbitrary files on the affected device.
Recommendations
For Cisco TelePresence Collaboration Endpoint (CE) Software, consider restricting access to the CLI until a fix is available.
For Cisco RoomOS Software, avoid using the CLI for sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Path traversal
Information Disclosure
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Roomos
Cisco Telepresence Collaboration Endpoint (Ce)