cbcvebase.

Cisco Roomos Software vulnerabilities

25 known vulnerabilities affecting cisco/cisco_roomos_software.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM11LOW1

Vulnerabilities

Page 2 of 2
CVE-2023-20092P4MEDIUMCVSS 4.4vN/A2024-11-15
CVE-2023-20092 [MEDIUM] CWE-61 CVE-2023-20092: Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, l Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. These vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing
nvd
CVE-2023-20004P4MEDIUMCVSS 4.4vN/A2024-11-15
CVE-2023-20004 [MEDIUM] CWE-59 CVE-2023-20004: Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, l Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. These vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing
nvd
CVE-2022-20794P4MEDIUMCVSS 4.7vn/a2022-05-04
CVE-2022-20794 [MEDIUM] CWE-601 CVE-2022-20794: Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Softwar Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilitie
nvd
CVE-2023-20094P4MEDIUMCVSS 4.3vN/A2024-11-15
CVE-2023-20094 [MEDIUM] CWE-125 CVE-2023-20094: A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacke A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A success
nvd
CVE-2021-34758P4LOWCVSS 3.3vn/a2021-10-06
CVE-2021-34758 [LOW] CWE-732 CVE-2021-34758: A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient access controls to a shared memory resource. An attacker
nvd
Cisco Roomos Software vulnerabilities | cvebase