QID 730493

Date Published: 2022-05-16

QID 730493: Cisco TelePresence Collaboration Endpoint Multiple Denial of Service (DoS)Vulnerability (cisco-sa-ROS-DOS-X7H7XhkK)

Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination.

Affected Products:
CVE-2022-20794
Prior to version 9.15.0.11
10 prior to version10.8.2.5

A successful exploit could allow the attacker to simulate a process crash, resulting in a DoS condition, or view sensitive information about the affected device.

  • CVSS V3 rated as Medium - 4.7 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ROS-DOS-X7H7XhkK for more information.

    CVEs related to QID 730493

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ROS-DOS-X7H7XhkK URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ROS-DOS-X7H7XhkK