QID 730627

Date Published: 2022-11-01

QID 730627: Cisco TelePresence Collaboration Endpoint Path Traversal Vulnerability (cisco-sa-roomos-trav-beFvCcyu)

A vulnerability in the video endpoint xAPI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.

Affected Products:
CVE-2022-20811
from 9 Prior to version 9.15.13.0
from 10 Prior to version 10.15.2.2

A successful exploit could allow the attacker to read and write arbitrary files in the device and escalate privileges from admin to root.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-roomos-trav-beFvCcyu for more information.

    CVEs related to QID 730627

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-roomos-trav-beFvCcyu URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-trav-beFvCcyu