Cisco Telepresence Collaboration Endpoint vulnerabilities
30 known vulnerabilities affecting cisco/telepresence_collaboration_endpoint.
Total CVEs
30
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH9MEDIUM20LOW1
Vulnerabilities
Page 2 of 2
CVE-2022-20768P4MEDIUMCVSS 4.9fixed in 10.15.2.22022-07-06
CVE-2022-20768 [MEDIUM] CWE-532 CVE-2022-20768: A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomO
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by ac
nvd
CVE-2023-20091P4MEDIUMCVSS 5.1≥ 9.0.0.0, < 9.15.17.42024-11-15
CVE-2023-20091 [MEDIUM] CWE-61 CVE-2023-20091: A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local a
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device.
This vulnerability is due to improper access controls on files that are on the local file system. An attacker could exploit this vulnerability by placing a symbolic l
nvd
CVE-2023-20002P4MEDIUMCVSS 4.4v8.1.1v8.3.0+33 more2023-01-20
CVE-2023-20002 [MEDIUM] CWE-918 CVE-2023-20002: A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local att
A vulnerability in Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to bypass access controls and conduct an SSRF attack through an affected device.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to a user of the
nvd
CVE-2020-26086P4MEDIUMCVSS 4.3fixed in 9.14.32020-11-06
CVE-2020-26086 [MEDIUM] CWE-668 CVE-2020-26086: A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) S
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper storage of sensitive information on an affected device. An attacker could exploit this vulnerabil
nvd
CVE-2023-20004P4MEDIUMCVSS 4.4≥ 9.0.0.0, < 9.15.17.42024-11-15
CVE-2023-20004 [MEDIUM] CWE-59 CVE-2023-20004: Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, l
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device.
These vulnerabilities are due to improper access controls on files that are on the local file system. An attacker could exploit these vulnerabilities by placing
nvd
CVE-2022-20794P4MEDIUMCVSS 4.7fixed in 9.15.0.11≥ 10.0.0.0, < 10.8.2.52022-05-04
CVE-2022-20794 [MEDIUM] CWE-601 CVE-2022-20794: Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Softwar
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilitie
nvd
CVE-2019-15273P4MEDIUMCVSS 4.4fixed in 9.8.12019-10-16
CVE-2019-15273 [MEDIUM] CWE-20 CVE-2019-15273: Multiple vulnerabilities in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could
Multiple vulnerabilities in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to overwrite arbitrary files. The vulnerabilities are due to insufficient permission enforcement. An attacker could exploit these vulnerabilities by authenticating as the remote support user and submitting malici
nvd
CVE-2019-15967P4MEDIUMCVSS 4.4fixed in 9.8.12019-11-26
CVE-2019-15967 [MEDIUM] CWE-284 CVE-2019-15967: A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Softwa
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, local attacker to enable audio recording without notifying users. The vulnerability is due to the presence of unnecessary debug commands. An attacker could exploit this vulnerability by gaining unrestricted access to t
nvd
CVE-2019-15962P4MEDIUMCVSS 4.4v7.3.18v8.3.7+3 more2019-10-16
CVE-2019-15962 [MEDIUM] CWE-275 CVE-2019-15962: A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission assignment. An attacker could exploit this vulnerability by logging in as the remotesupport user and writing fi
nvd
CVE-2021-34758P4LOWCVSS 3.3fixed in 10.7.22021-10-06
CVE-2021-34758 [LOW] CWE-732 CVE-2021-34758: A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software
A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient access controls to a shared memory resource. An attacker
nvd
← Previous2 / 2