PT-2022-5342 · Cisco · Cisco Roomos+1

Jason Crowder

·

Published

2022-10-19

·

Updated

2022-10-31

·

CVE-2022-20955

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco TelePresence Collaboration Endpoint (CE) Software (affected versions not specified) Cisco RoomOS Software (affected versions not specified)
Description The issue is related to inadequate access control in the command-line interface (CLI) of the Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS, allowing an attacker to overwrite arbitrary files. This could also enable path traversal attacks, allowing the viewing of sensitive data or writing of arbitrary files on the affected device.
Recommendations For Cisco TelePresence Collaboration Endpoint (CE) Software, consider restricting access to the CLI until a fix is available. For Cisco RoomOS Software, avoid using the CLI for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Path traversal

Information Disclosure

Link Following

Weakness Enumeration

Related Identifiers

BDU:2022-06656
CVE-2022-20955

Affected Products

Cisco Roomos
Cisco Telepresence Collaboration Endpoint (Ce)