CVE-2022-20768
Severity
4.9MEDIUM
EPSS
0.2%
top 56.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 6
Latest updateJul 7
Description
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow th…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-hh3r-h56v-mwcg: A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote at↗2022-07-07
CVEList▶
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability↗2022-07-06
📋Vendor Advisories
1Cisco▶
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability↗2022-07-06