CVE-2022-20793

CWE-3254 documents4 sources
Severity
6.8MEDIUM
EPSS
0.1%
top 70.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. This vulnerability is due to insufficient identity verification. An attacker could exploit this vulnerability by impersonating a legitimate device and responding to the pairing broadcast from an affected device. A successful exploit could allow the attacker to access

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-w4wv-5x8m-w2cf: A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, re2024-11-15
CVEList
Cisco Touch 10 Device Insufficient Identity Verification Vulnerability2024-11-15

📋Vendor Advisories

1
Cisco
Cisco Touch 10 Devices Insufficient Identity Verification Vulnerability2022-10-05
CVE-2022-20793 (MEDIUM CVSS 6.8) | A vulnerability in pairing process | cvebase.io