CVE-2022-20931
published 2024-11-15CVE-2022-20931: A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to…
PriorityP434medium6.5CVSS 3.1
AVAACLPRNUINSUCNIHAN
EPSS
0.27%
18.0th percentile
A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device.
This vulnerability is due to insufficient version control. An attacker could exploit this vulnerability by installing an older version of Cisco TelePresence CE Software on an affected device. A successful exploit could allow the attacker to take advantage of vulnerabilities in older versions of the software.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-92gj-2wf7-h87v: A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker
ghsa_unreviewed·2024-11-15
CVE-2022-20931 [MEDIUM] CWE-527 GHSA-92gj-2wf7-h87v: A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker
A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device.
This vulnerability is due to insufficient version control. An attacker could exploit this vulnerability by installing an older version of Cisco TelePresence CE Software on an affected device. A successful exploit could allow the attacker to take advantage of vulnerabilities in older versions of the software.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Cisco
Cisco Touch 10 Devices Downgrade Vulnerability
vendor_cisco·2022-10-05·CVSS 6.5
CVE-2022-20931 [MEDIUM] CWE-527 Cisco Touch 10 Devices Downgrade Vulnerability
Cisco Touch 10 Devices Downgrade Vulnerability
A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device.
This vulnerability is due to insufficient version control. An attacker could exploit this vulnerability by installing an older version of Cisco TelePresence CE Software on an affected device. A successful exploit could allow the attacker to take advantage of vulnerabilities in older versions of the software.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/
Cisco
Cisco Touch 10 Devices Downgrade Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20931 Cisco Touch 10 Devices Downgrade Vulnerability
CVE-2022-20931: Cisco Touch 10 Devices Downgrade Vulnerability
A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device. This vulnerability is due to insufficient version control. An attacker could exploit this vulnerability by installing an older version of Cisco TelePresence CE Software on an affected device. A successful exploit could allow the attacker to take advantage of vulnerabilities in older versions of the software. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-527, CWE-527
Bug IDs: CSCvw12012
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-15
Published