CVE-2020-3336
published 2020-06-18CVE-2020-3336: A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated…
PriorityP344high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.07%
79.3th percentile
A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access to the root filesystem. The vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending requests with malformed parameters to the system using the console, Secure Shell (SSH), or web API. A successful exploit could allow the attacker to modify the device configuration or cause a DoS.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_telepresence_ce_software | — | — |
| cisco | telepresence_collaboration_endpoint | < 9.9.4 | 9.9.4 |
| cisco | telepresence_collaboration_endpoint | 9.10.0 – 9.10.2 | — |
| cisco | telepresence_collaboration_endpoint | 9.12.0 – 9.12.3 | — |
| cisco | telepresence_collaboration_endpoint_and_roomos | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xm4r-pr55-hfw3: A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authent
ghsa_unreviewed·2022-05-24
CVE-2020-3336 [HIGH] GHSA-xm4r-pr55-hfw3: A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authent
A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access to the root filesystem. The vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending requests with malformed parameters to the system using the console, Secure Shell (SSH), or web API. A successful exploit could allow the attacker to modify the device configuration or cause a DoS.
Cisco
Cisco TelePresence Collaboration Endpoint and RoomOS Software Command Injection Vulnerability
vendor_cisco·2020-06-17·CVSS 7.2
CVE-2020-3336 [HIGH] CWE-78 Cisco TelePresence Collaboration Endpoint and RoomOS Software Command Injection Vulnerability
Cisco TelePresence Collaboration Endpoint and RoomOS Software Command Injection Vulnerability
A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access to the root filesystem.
The vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending requests with malformed parameters to the system using the console, Secure Shell (SSH), or web API. A successful exploit could allow the attacker to modify the device configuration or cause a DoS.
Cisco has released software updates that address this vulnerability. There ar
Cisco
Cisco TelePresence Collaboration Endpoint and RoomOS Software Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3336 Cisco TelePresence Collaboration Endpoint and RoomOS Software Command Injection Vulnerability
CVE-2020-3336: Cisco TelePresence Collaboration Endpoint and RoomOS Software Command Injection Vulnerability
A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access to the root filesystem. The vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending requests with malformed parameters to the system using the console, Secure Shell (SSH), or web API. A successful exploit could allow the attacker to modify the device configuration or cause a DoS. Cisco has released software updates that address this vulnerabil
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-18
Published