PT-2023-1108 · Cisco · Cisco Telepresence Collaboration Endpoint+1

Deklan Evans

·

Published

2023-01-11

·

Updated

2024-01-25

·

CVE-2023-20008

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS (affected versions not specified)
Description The issue is related to inadequate access control in the command-line interface (CLI) of the Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS, allowing an authenticated, local attacker to overwrite arbitrary files on the local system of an affected device. This is due to improper access controls on files in the local file system. An attacker could exploit this by placing a symbolic link in a specific location on the local file system, potentially allowing them to overwrite arbitrary files.
Recommendations For Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS, consider restricting access to the CLI to minimize the risk of exploitation until a fix is available. As a temporary workaround, avoid using the CLI for sensitive operations on affected devices until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2023-00302
CVE-2023-20008

Affected Products

Cisco Roomos
Cisco Telepresence Collaboration Endpoint