CVE-2020-3143
Summary
| CVE | CVE-2020-3143 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-23 01:15:00 UTC |
| Updated | 2020-10-05 14:43:00 UTC |
| Description | A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the xAPI of the affected software. An attacker could exploit this vulnerability by sending a crafted request to the xAPI. A successful exploit could allow the attacker to read and write arbitrary files in the system. To exploit this vulnerability, an attacker would need either an In-Room Control or administrator account. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Ex60 | - | All | All | All |
| Hardware | Cisco | Ex60 | - | All | All | All |
| Operating System | Cisco | Ex60 Firmware | - | All | All | All |
| Operating System | Cisco | Ex60 Firmware | - | All | All | All |
| Hardware | Cisco | Ex90 | - | All | All | All |
| Hardware | Cisco | Ex90 | - | All | All | All |
| Operating System | Cisco | Ex90 Firmware | - | All | All | All |
| Operating System | Cisco | Ex90 Firmware | - | All | All | All |
| Hardware | Cisco | Sx10 | - | All | All | All |
| Hardware | Cisco | Sx10 | - | All | All | All |
| Operating System | Cisco | Sx10 Firmware | - | All | All | All |
| Operating System | Cisco | Sx10 Firmware | - | All | All | All |
| Hardware | Cisco | Sx20 | - | All | All | All |
| Hardware | Cisco | Sx20 | - | All | All | All |
| Operating System | Cisco | Sx20 Firmware | - | All | All | All |
| Operating System | Cisco | Sx20 Firmware | - | All | All | All |
| Hardware | Cisco | Sx80 | - | All | All | All |
| Hardware | Cisco | Sx80 | - | All | All | All |
| Operating System | Cisco | Sx80 Firmware | - | All | All | All |
| Operating System | Cisco | Sx80 Firmware | - | All | All | All |
| Hardware | Cisco | Telepresence Codec C40 | - | All | All | All |
| Hardware | Cisco | Telepresence Codec C40 | - | All | All | All |
| Operating System | Cisco | Telepresence Codec C40 Firmware | - | All | All | All |
| Operating System | Cisco | Telepresence Codec C40 Firmware | - | All | All | All |
| Hardware | Cisco | Telepresence Codec C60 | - | All | All | All |
| Hardware | Cisco | Telepresence Codec C60 | - | All | All | All |
| Operating System | Cisco | Telepresence Codec C60 Firmware | - | All | All | All |
| Operating System | Cisco | Telepresence Codec C60 Firmware | - | All | All | All |
| Hardware | Cisco | Telepresence Codec C90 | - | All | All | All |
| Hardware | Cisco | Telepresence Codec C90 | - | All | All | All |
| Operating System | Cisco | Telepresence Codec C90 Firmware | - | All | All | All |
| Operating System | Cisco | Telepresence Codec C90 Firmware | - | All | All | All |
| Hardware | Cisco | Telepresence Mx200 | - | All | All | All |
| Hardware | Cisco | Telepresence Mx200 | - | All | All | All |
| Operating System | Cisco | Telepresence Mx200 Firmware | - | All | All | All |
| Operating System | Cisco | Telepresence Mx200 Firmware | - | All | All | All |
| Hardware | Cisco | Telepresence Mx300 | - | All | All | All |
| Hardware | Cisco | Telepresence Mx300 | - | All | All | All |
| Operating System | Cisco | Telepresence Mx300 Firmware | - | All | All | All |
| Operating System | Cisco | Telepresence Mx300 Firmware | - | All | All | All |
| Hardware | Cisco | Telepresence Mx700 | - | All | All | All |
| Hardware | Cisco | Telepresence Mx700 | - | All | All | All |
| Operating System | Cisco | Telepresence Mx700 Firmware | - | All | All | All |
| Operating System | Cisco | Telepresence Mx700 Firmware | - | All | All | All |
| Hardware | Cisco | Telepresence Mx800 | - | All | All | All |
| Hardware | Cisco | Telepresence Mx800 | - | All | All | All |
| Operating System | Cisco | Telepresence Mx800 Firmware | - | All | All | All |
| Operating System | Cisco | Telepresence Mx800 Firmware | - | All | All | All |
| Hardware | Cisco | Webex Board 55 | - | All | All | All |
| Hardware | Cisco | Webex Board 55 | - | All | All | All |
| Hardware | Cisco | Webex Board 55s | - | All | All | All |
| Hardware | Cisco | Webex Board 55s | - | All | All | All |
| Operating System | Cisco | Webex Board 55s Firmware | - | All | All | All |
| Operating System | Cisco | Webex Board 55s Firmware | - | All | All | All |
| Operating System | Cisco | Webex Board 55 Firmware | - | All | All | All |
| Operating System | Cisco | Webex Board 55 Firmware | - | All | All | All |
| Hardware | Cisco | Webex Board 70 | - | All | All | All |
| Hardware | Cisco | Webex Board 70 | - | All | All | All |
| Hardware | Cisco | Webex Board 70s | - | All | All | All |
| Hardware | Cisco | Webex Board 70s | - | All | All | All |
| Operating System | Cisco | Webex Board 70s Firmware | - | All | All | All |
| Operating System | Cisco | Webex Board 70s Firmware | - | All | All | All |
| Operating System | Cisco | Webex Board 70 Firmware | - | All | All | All |
| Operating System | Cisco | Webex Board 70 Firmware | - | All | All | All |
| Hardware | Cisco | Webex Board 85s | - | All | All | All |
| Hardware | Cisco | Webex Board 85s | - | All | All | All |
| Operating System | Cisco | Webex Board 85s Firmware | - | All | All | All |
| Operating System | Cisco | Webex Board 85s Firmware | - | All | All | All |
| Hardware | Cisco | Webex Dx70 | - | All | All | All |
| Hardware | Cisco | Webex Dx70 | - | All | All | All |
| Operating System | Cisco | Webex Dx70 Firmware | - | All | All | All |
| Operating System | Cisco | Webex Dx70 Firmware | - | All | All | All |
| Hardware | Cisco | Webex Dx80 | - | All | All | All |
| Hardware | Cisco | Webex Dx80 | - | All | All | All |
| Operating System | Cisco | Webex Dx80 Firmware | - | All | All | All |
| Operating System | Cisco | Webex Dx80 Firmware | - | All | All | All |
| Hardware | Cisco | Webex Room 55 | - | All | All | All |
| Hardware | Cisco | Webex Room 55 | - | All | All | All |
| Operating System | Cisco | Webex Room 55 Firmware | - | All | All | All |
| Operating System | Cisco | Webex Room 55 Firmware | - | All | All | All |
| Hardware | Cisco | Webex Room 70 | - | All | All | All |
| Hardware | Cisco | Webex Room 70 | - | All | All | All |
| Operating System | Cisco | Webex Room 70 Firmware | - | All | All | All |
| Operating System | Cisco | Webex Room 70 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco TelePresence Collaboration Endpoint, TelePresence Codec, and RoomOS Software Path Traversal Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.