CVE-2020-26068
published 2020-11-18CVE-2020-26068: A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an…
PriorityP336medium6.5CVSS 3.1
AVNACLPRHUINSUCHIHAN
EPSS
0.72%
49.8th percentile
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An attacker could exploit this vulnerability by using the xAPI service to generate a specific token. A successful exploit could allow the attacker to use the generated token to enable experimental features on the device that should not be available to users.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | telepresence_ce | — | — |
| cisco | telepresence_collaboration_endpoint | >= 9.10.0 < 9.10.3 | 9.10.3 |
| cisco | telepresence_collaboration_endpoint | >= 9.12.0 < 9.12.4 | 9.12.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
vendor_cisco5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m8hx-3q8c-m23r: A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to gener
ghsa_unreviewed·2022-05-24
CVE-2020-26068 [MEDIUM] CWE-639 GHSA-m8hx-3q8c-m23r: A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to gener
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An attacker could exploit this vulnerability by using the xAPI service to generate a specific token. A successful exploit could allow the attacker to use the generated token to enable experimental features on the device that should not be available to users.
Cisco
Cisco Telepresence CE Software and RoomOS Software Unauthorized Token Generation Vulnerability
vendor_cisco·2020-11-18·CVSS 5.5
CVE-2020-26068 [MEDIUM] CWE-639 Cisco Telepresence CE Software and RoomOS Software Unauthorized Token Generation Vulnerability
Cisco Telepresence CE Software and RoomOS Software Unauthorized Token Generation Vulnerability
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device.
The vulnerability is due to insufficient access authorization. An attacker could exploit this vulnerability by using the xAPI service to generate a specific token. A successful exploit could allow the attacker to use the generated token to enable experimental features on the device that should not be available to users.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec
Cisco
Cisco Telepresence CE Software and RoomOS Software Unauthorized Token Generation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-26068 Cisco Telepresence CE Software and RoomOS Software Unauthorized Token Generation Vulnerability
CVE-2020-26068: Cisco Telepresence CE Software and RoomOS Software Unauthorized Token Generation Vulnerability
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An attacker could exploit this vulnerability by using the xAPI service to generate a specific token. A successful exploit could allow the attacker to use the generated token to enable experimental features on the device that should not be available to users. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-639, CWE-639
Bug IDs: CSCvu31646
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-11-18
Published