CVE-2023-20094

Severity
4.3MEDIUM
EPSS
0.1%
top 68.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information. Note: This vulnerability only affects Cisco

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-jrhg-66xp-fmhv: A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected dev2024-11-15
CVEList
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability2024-11-15

📋Vendor Advisories

1
Cisco
Cisco TelePresence Collaboration Endpoint and RoomOS Arbitrary File Write Vulnerabilities2023-04-19
CVE-2023-20094 (MEDIUM CVSS 4.3) | A vulnerability in Cisco TelePresen | cvebase.io