Cisco Roomos Software vulnerabilities
25 known vulnerabilities affecting cisco/cisco_roomos_software.
Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM11LOW1
Vulnerabilities
Page 1 of 2
CVE-2026-20150P3HIGHCVSS 8.8vRoomOS 10.11.2.2vRoomOS 10.15.2.2+66 more2026-07-15
CVE-2026-20150 [HIGH] CWE-284 CVE-2026-20150: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20150 are related to impr
nvd
CVE-2026-20119P3HIGHCVSS 7.5vRoomOS 10.11.2.2vRoomOS 10.15.2.2+49 more2026-02-04
CVE-2026-20119 [HIGH] CWE-1287 CVE-2026-20119: A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) So
A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient validation of input received by an affected device. An attac
nvd
CVE-2026-20156P3HIGHCVSS 8.1vRoomOS 10.11.2.2vRoomOS 10.15.2.2+66 more2026-07-15
CVE-2026-20156 [HIGH] CWE-119 CVE-2026-20156: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20156 are related to impr
nvd
CVE-2022-20811P3HIGHCVSS 7.2vn/a2022-10-26
CVE-2022-20811 [HIGH] CWE-200 CVE-2022-20811: Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2022-20764P3HIGHCVSS 8.1vn/a2022-05-04
CVE-2022-20764 [HIGH] CWE-601 CVE-2022-20764: Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Softwar
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilities,
nvd
CVE-2022-20783P3HIGHCVSS 7.5vn/a2022-04-21
CVE-2022-20783 [HIGH] CWE-1287 CVE-2022-20783: A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint
A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulner
nvd
CVE-2026-20158P3HIGHCVSS 7.5vRoomOS 10.11.2.2vRoomOS 10.15.2.2+66 more2026-07-15
CVE-2026-20158 [HIGH] CWE-664 CVE-2026-20158: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20158 are related to impr
nvd
CVE-2026-20157P3HIGHCVSS 7.5vRoomOS 10.11.2.2vRoomOS 10.15.2.2+66 more2026-07-15
CVE-2026-20157 [HIGH] CWE-311 CVE-2026-20157: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20157 are related to miss
nvd
CVE-2026-20153P3HIGHCVSS 7.5vRoomOS 10.11.2.2vRoomOS 10.15.2.2+66 more2026-07-15
CVE-2026-20153 [HIGH] CWE-20 CVE-2026-20153: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20153 are related to impro
nvd
CVE-2026-20187P3HIGHCVSS 7.5vRoomOS 10.11.2.2vRoomOS 10.15.2.2+65 more2026-07-15
CVE-2026-20187 [HIGH] CWE-703 CVE-2026-20187: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20187 are related to impr
nvd
CVE-2022-20793P3MEDIUMCVSS 6.8vN/A2024-11-15
CVE-2022-20793 [MEDIUM] CWE-325 CVE-2022-20793: A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Ci
A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device.
This vulnerability is due to insufficient identity verification. An attacker could exploit this vulnerability by imper
nvd
CVE-2022-20954P3HIGHCVSS 7.1vn/a2022-10-26
CVE-2022-20954 [HIGH] CWE-200 CVE-2022-20954: Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2022-20955P3HIGHCVSS 7.1vn/a2022-10-26
CVE-2022-20955 [HIGH] CWE-200 CVE-2022-20955: Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2023-20090P3MEDIUMCVSS 6.7vN/A2024-11-15
CVE-2023-20090 [MEDIUM] CWE-27 CVE-2023-20090: A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to
A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device.
This vulnerability is due to improper access control on certain CLI commands. An attacker could exploit this vulnerability by running a series of crafted commands. A successful exploit could allow the a
nvd
CVE-2023-20008P4HIGHCVSS 7.1vRoomOS 10.3.2.0vRoomOS 10.3.4.0+5 more2023-01-20
CVE-2023-20008 [HIGH] CWE-59 CVE-2023-20008: A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to overwrite arbitrary files on the local system of an affected device.
This vulnerability is due to improper access controls on files that are in the local file system. An attacker could exploit this vulnerability by placing a symbolic
nvd
CVE-2022-20776P4MEDIUMCVSS 6.7vn/a2022-10-26
CVE-2022-20776 [MEDIUM] CWE-200 CVE-2022-20776: Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2022-20953P4MEDIUMCVSS 5.5vn/a2022-10-26
CVE-2022-20953 [MEDIUM] CWE-200 CVE-2022-20953: Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2025-20329P4MEDIUMCVSS 4.9vRoomOS 10.11.2.2vRoomOS 10.15.2.2+46 more2025-10-15
CVE-2025-20329 [MEDIUM] CWE-532 CVE-2025-20329: A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability exists becaus
nvd
CVE-2022-20768P4MEDIUMCVSS 4.9vn/a2022-07-06
CVE-2022-20768 [MEDIUM] CWE-532 CVE-2022-20768: A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomO
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by ac
nvd
CVE-2023-20002P4MEDIUMCVSS 4.4vRoomOS 10.3.2.0vRoomOS 10.3.4.0+5 more2023-01-20
CVE-2023-20002 [MEDIUM] CWE-918 CVE-2023-20002: A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local att
A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSRF attack through an affected device.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a user of the
nvd
1 / 2Next →