QID 730492

Date Published: 2022-05-16

QID 730492: Cisco TelePresence Collaboration Endpoint Multiple Denial of Service (DoS)Vulnerability (cisco-sa-ROS-DOS-X7H7XhkK)

Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination.

Affected Products:CVE-2022-20764
Cisco Telepresence CE Software or Cisco RoomOS Software.
Earlier than version 10.8.2.5
QID Detection Logic (Unauthenticated):
The check matches Cisco TelePresence CE Software version retrieved via SNMP Banner.

A successful exploit could allow the attacker to simulate a process crash, resulting in a DoS condition, or view sensitive information about the affected device.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    Customers are advised to refer to cisco-sa-ROS-DOS-X7H7XhkK for more information.

    CVEs related to QID 730492

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ROS-DOS-X7H7XhkK URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ROS-DOS-X7H7XhkK