CVE-2023-20002
published 2023-01-20CVE-2023-20002: A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSRF attack…
PriorityP424medium4.4CVSS 3.1
AVLACLPRLUINSUCLILAN
EPSS
0.16%
5.7th percentile
A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSRF attack through an affected device.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a user of the web application. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected system.
Affected
91 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_roomos_software | — | — |
| cisco | cisco_roomos_software | — | — |
| cisco | cisco_roomos_software | — | — |
| cisco | cisco_roomos_software | — | — |
| cisco | cisco_roomos_software | — | — |
| cisco | cisco_roomos_software | — | — |
| cisco | cisco_roomos_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
| cisco | cisco_telepresence_endpoint_software | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
vendor_cisco4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
vendor_cisco·2023-01-11·CVSS 4.4
CVE-2023-20002 [MEDIUM] CWE-59 Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK
Cisco
Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2023-20002 Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
CVE-2023-20002: Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-59, CWE-918, CWE-59, CWE-918
Bug IDs: CSCwc47201, CSCwc85914, CSCwc85914, CSCwc47201
GHSA
XWiki Platform's tags on non-viewable pages can be revealed to users
ghsa·2023-06-20
CVE-2023-34466 [MEDIUM] CWE-200 XWiki Platform's tags on non-viewable pages can be revealed to users
XWiki Platform's tags on non-viewable pages can be revealed to users
### Impact
Tags from pages not viewable to the current user are leaked by the tags API.
This information can also be exploited to infer the document reference of non-viewable pages.
### Patches
This vulnerability has been patched in XWiki 14.4.8, 14.10.4, and 15.0 RC1.
### Workarounds
There is no workaround apart from upgrading to a fixed version.
### References
- https://jira.xwiki.org/browse/XWIKI-20002
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:[email protected])
GHSA
GHSA-2m96-fxj3-h8fg: A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSR
ghsa_unreviewed·2023-01-20
CVE-2023-20002 [MEDIUM] CWE-918 GHSA-2m96-fxj3-h8fg: A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSR
A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSRF attack through an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a user of the web application. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-20
Published