cbcvebase.
CVE-2020-3336
published 2020-06-18

CVE-2020-3336: A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated…

PriorityP344high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.07%
79.3th percentile
A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access to the root filesystem. The vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending requests with malformed parameters to the system using the console, Secure Shell (SSH), or web API. A successful exploit could allow the attacker to modify the device configuration or cause a DoS.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_telepresence_ce_software
ciscotelepresence_collaboration_endpoint< 9.9.49.9.4
ciscotelepresence_collaboration_endpoint9.10.0 – 9.10.2
ciscotelepresence_collaboration_endpoint9.12.0 – 9.12.3
ciscotelepresence_collaboration_endpoint_and_roomos

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.