QID 730629

Date Published: 2022-11-01

QID 730629: Cisco TelePresence Collaboration Endpoint Path Traversal Vulnerability (cisco-sa-roomos-trav-beFvCcyu) (CVE-2022-20776)

A vulnerability in the video endpoint xAPI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.

Affected Products:
CVE-2022-20776
from 9 Prior to version 10.20.1

A successful exploit could allow the attacker to read and write arbitrary files in the system and escalate privileges from admin to root.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-roomos-trav-beFvCcyu for more information.

    CVEs related to QID 730629

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-roomos-trav-beFvCcyu URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-trav-beFvCcyu