Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities

cisco-sa-roomos-dkjGFgRK · Medium · Published · Updated

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address these vulnerabilities.

CVEsCVE-2023-20002, CVE-2023-20008
Cisco Bug IDsCSCwc47201, CSCwc85914
CVSS ScoreBase 4.4
Base 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:X/RL:X/RC:X
Base 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco RoomOS Software, Cisco TelePresence Endpoint Software (TC/CE)

Related Products

Product CVE Evidence
Cisco TelePresence Endpoint Software (TC/CE) CVE-2023-20008 Cisco OpenVuln
Cisco TelePresence Endpoint Software (TC/CE) CVE-2023-20002 Cisco OpenVuln
Cisco TelePresence CVE-2023-20008 Cisco OpenVuln
Cisco TelePresence CVE-2023-20002 Cisco OpenVuln
Cisco RoomOS Software CVE-2023-20008 Cisco OpenVuln
Cisco RoomOS Software CVE-2023-20002 Cisco OpenVuln