Cisco Roomos vulnerabilities

18 known vulnerabilities affecting cisco/roomos.

Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM12LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-20329MEDIUMCVSS 4.9≥ 10.0.0.0, < 11.32.2.12025-10-15
CVE-2025-20329 [MEDIUM] CWE-532 CVE-2025-20329: A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability exists becaus
nvd
CVE-2023-20092MEDIUMCVSS 4.4≥ 10.0.1.2, < 11.1.2.42024-11-15
CVE-2023-20092 [MEDIUM] CWE-61 CVE-2023-20092: Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, l Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. These vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing
nvd
CVE-2023-20093MEDIUMCVSS 4.4≥ 10.0.1.2, < 11.1.3.12024-11-15
CVE-2023-20093 [MEDIUM] CVE-2023-20093: Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, l Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. These vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing a symb
nvd
CVE-2023-20004MEDIUMCVSS 4.4≥ 10.0.1.2, < 11.1.2.42024-11-15
CVE-2023-20004 [MEDIUM] CWE-59 CVE-2023-20004: Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, l Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. These vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing
nvd
CVE-2023-20091MEDIUMCVSS 5.1≥ 10.0.1.2, < 11.1.3.12024-11-15
CVE-2023-20091 [MEDIUM] CWE-61 CVE-2023-20091: A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local a A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. This vulnerability is due to improper access controls on files that are on the local file system. An attacker could exploit this vulnerability by placing a symbolic l
nvd
CVE-2023-20090MEDIUMCVSS 6.7≥ 10.0.1.2, < 11.1.2.42024-11-15
CVE-2023-20090 [MEDIUM] CWE-27 CVE-2023-20090: A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to improper access control on certain CLI commands. An attacker could exploit this vulnerability by running a series of crafted commands. A successful exploit could allow the a
nvd
CVE-2023-20008HIGHCVSS 7.1v10.3.2.0v10.3.4.0+5 more2023-01-20
CVE-2023-20008 [HIGH] CWE-59 CVE-2023-20008: A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access controls on files that are in the local file system. An attacker could exploit this vulnerability by placing a symbolic
nvd
CVE-2023-20002MEDIUMCVSS 4.4v10.3.2.0v10.3.4.0+5 more2023-01-20
CVE-2023-20002 [MEDIUM] CWE-918 CVE-2023-20002: A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local att A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSRF attack through an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a user of the
nvd
CVE-2022-20811HIGHCVSS 7.2fixed in 10.15.12022-10-26
CVE-2022-20811 [HIGH] CWE-200 CVE-2022-20811: Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2022-20776MEDIUMCVSS 6.7fixed in 10.20.12022-10-26
CVE-2022-20776 [MEDIUM] CWE-200 CVE-2022-20776: Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2022-20764HIGHCVSS 8.1fixed in 2021-052022-05-04
CVE-2022-20764 [HIGH] CWE-601 CVE-2022-20764: Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Softwar Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilities,
nvd
CVE-2022-20794MEDIUMCVSS 4.7fixed in 2021-052022-05-04
CVE-2022-20794 [MEDIUM] CWE-601 CVE-2022-20794: Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Softwar Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilitie
nvd
CVE-2022-20783HIGHCVSS 7.5fixed in 20222022-04-21
CVE-2022-20783 [HIGH] CWE-1287 CVE-2022-20783: A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulner
nvd
CVE-2021-34758LOWCVSS 3.3fixed in 10.7.1.22021-10-06
CVE-2021-34758 [LOW] CWE-732 CVE-2021-34758: A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient access controls to a shared memory resource. An attacker
nvd
CVE-2021-1532MEDIUMCVSS 6.5fixed in 10.3.12021-05-06
CVE-2021-1532 [MEDIUM] CWE-22 CVE-2021-1532: A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) S A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability is due to insufficient path validation of command arguments. An attacker could exploit this v
nvd
CVE-2019-15288HIGHCVSS 8.8fixed in 2019-09-drop12019-11-26
CVE-2019-15288 [HIGH] CWE-20 CVE-2019-15288: A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Cod A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privileges to an unrestricted user of the restricted shell. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerabili
nvd
CVE-2019-15967MEDIUMCVSS 4.4fixed in 2019-09-drop12019-11-26
CVE-2019-15967 [MEDIUM] CWE-284 CVE-2019-15967: A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Softwa A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, local attacker to enable audio recording without notifying users. The vulnerability is due to the presence of unnecessary debug commands. An attacker could exploit this vulnerability by gaining unrestricted access to t
nvd
CVE-2019-12622MEDIUMCVSS 5.5≤ 9.7.2fixed in 9.8.02019-08-21
CVE-2019-12622 [MEDIUM] CWE-275 CVE-2019-12622: A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permission restrictions on a specific process. An attacker could exploit this vulnerability by logging in to an affected device with remote support credential
nvd