CVE-2022-20794

Severity
4.7MEDIUM
EPSS
0.2%
top 54.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 4
Latest updateMay 5

Description

Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDcisco/telepresence_collaboration_endpoint10.0.0.010.8.2.5+1
NVDcisco/roomos< 2021-05

🔴Vulnerability Details

2
GHSA
GHSA-73qr-385m-w7v6: Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote a2022-05-05
CVEList
Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities2022-05-04

📋Vendor Advisories

1
Cisco
Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities2022-05-04
CVE-2022-20794 (MEDIUM CVSS 4.7) | Multiple vulnerabilities in the web | cvebase.io