Cisco Telepresence Endpoint Software vulnerabilities
14 known vulnerabilities affecting cisco/cisco_telepresence_endpoint_software.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM12
Vulnerabilities
Page 1 of 1
CVE-2026-20119HIGHCVSS 7.5vCE9.3.0vCE9.10.2+33 more2026-02-04
CVE-2026-20119 [HIGH] CWE-1287 CVE-2026-20119: A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) So
A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient validation of input received by an affected device. An attac
cvelistv5nvd
CVE-2023-20090MEDIUMCVSS 6.7vCE9.10.2vCE9.1.4+41 more2024-11-15
CVE-2023-20090 [MEDIUM] CWE-27 CVE-2023-20090: A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to
A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device.
This vulnerability is due to improper access control on certain CLI commands. An attacker could exploit this vulnerability by running a series of crafted commands. A successful exploit could allow the a
cvelistv5nvd
CVE-2023-20004MEDIUMCVSS 4.4vCE9.10.2vCE9.1.4+41 more2024-11-15
CVE-2023-20004 [MEDIUM] CWE-59 CVE-2023-20004: Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, l
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device.
These vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing
cvelistv5nvd
CVE-2023-20094MEDIUMCVSS 4.3vN/A2024-11-15
CVE-2023-20094 [MEDIUM] CWE-125 CVE-2023-20094: A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacke
A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device.
This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A success
cvelistv5nvd
CVE-2023-20092MEDIUMCVSS 4.4vN/A2024-11-15
CVE-2023-20092 [MEDIUM] CWE-61 CVE-2023-20092: Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, l
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device.
These vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing
cvelistv5nvd
CVE-2022-20931MEDIUMCVSS 6.5vCE9.10.2vCE9.1.4+39 more2024-11-15
CVE-2022-20931 [MEDIUM] CWE-527 CVE-2022-20931: A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 1
A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device.
This vulnerability is due to insufficient version control. An attacker could exploit this vulnerability by installing an older version
cvelistv5nvd
CVE-2023-20091MEDIUMCVSS 5.1vCE9.10.2vCE9.1.4+41 more2024-11-15
CVE-2023-20091 [MEDIUM] CWE-61 CVE-2023-20091: A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local a
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device.
This vulnerability is due to improper access controls on files that are on the local file system. An attacker could exploit this vulnerability by placing a symbolic l
cvelistv5nvd
CVE-2022-20793MEDIUMCVSS 6.8vCE9.10.2vCE9.1.4+39 more2024-11-15
CVE-2022-20793 [MEDIUM] CWE-325 CVE-2022-20793: A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Ci
A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device.
This vulnerability is due to insufficient identity verification. An attacker could exploit this vulnerability by imper
cvelistv5nvd
CVE-2023-20093MEDIUMCVSS 4.4vN/A2024-11-15
CVE-2023-20093 [MEDIUM] CWE-61 Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device.
These vulnerabilities are due to improper access controls on files that ar
cvelistv5
CVE-2023-20008HIGHCVSS 7.1vCE9.0.1vCE9.1.1+42 more2023-01-20
CVE-2023-20008 [HIGH] CWE-59 CVE-2023-20008: A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to overwrite arbitrary files on the local system of an affected device.
This vulnerability is due to improper access controls on files that are in the local file system. An attacker could exploit this vulnerability by placing a symbolic
cvelistv5nvd
CVE-2023-20002MEDIUMCVSS 4.4vCE9.0.1vCE9.1.1+39 more2023-01-20
CVE-2023-20002 [MEDIUM] CWE-918 CVE-2023-20002: A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local att
A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSRF attack through an affected device.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a user of the
cvelistv5nvd
CVE-2021-1532MEDIUMCVSS 6.5vn/a2021-05-06
CVE-2021-1532 [MEDIUM] CWE-22 CVE-2021-1532: A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) S
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability is due to insufficient path validation of command arguments. An attacker could exploit this v
cvelistv5nvd
CVE-2020-26068MEDIUMCVSS 6.5vn/a2020-11-18
CVE-2020-26068 [MEDIUM] CWE-639 CVE-2020-26068: A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software coul
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An attacker could exploit this vulnerability by using the xAPI service to generate a specific
cvelistv5nvd
CVE-2020-26086MEDIUMCVSS 4.3vn/a2020-11-06
CVE-2020-26086 [MEDIUM] CWE-668 CVE-2020-26086: A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) S
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper storage of sensitive information on an affected device. An attacker could exploit this vulnerabil
cvelistv5nvd