CVE-2022-20768

Severity
4.9MEDIUM
EPSS
0.2%
top 56.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 6
Latest updateJul 7

Description

A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow th

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-hh3r-h56v-mwcg: A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote at2022-07-07
CVEList
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability2022-07-06

📋Vendor Advisories

1
Cisco
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability2022-07-06
CVE-2022-20768 (MEDIUM CVSS 4.9) | A vulnerability in the logging comp | cvebase.io