QID 730564

Date Published: 2022-07-11

QID 730564: Cisco TelePresence Collaboration Endpoint Information Disclosure Vulnerability (cisco-sa-roomos-infodisc-YOTz9Ct7)

A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.

Affected Products:
CVE-2022-20794
Prior to version 10
10 prior to version10.15.2.2
Note : We are not checking whether the Extended Logging Mode is Enabled or not hence marked it as practice.

A successful exploit could allow the attacker to use those credentials to access confidential information, some of which may contain personally identifiable information (PII).

  • CVSS V3 rated as Medium - 4.9 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-roomos-infodisc-YOTz9Ct7 for more information.

    CVEs related to QID 730564

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-roomos-infodisc-YOTz9Ct7 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-infodisc-YOTz9Ct7