QID 730630

Date Published: 2022-11-01

QID 730630: Cisco TelePresence Collaboration Endpoint Arbitrary File Write Vulnerability (cisco-sa-roomos-trav-beFvCcyu)

A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an authenticated, local attacker to overwrite arbitrary files on the local system.

Affected Products:
CVE-2022-20953, CVE-2022-20954, and CVE-2022-20955
from 9 Prior to version 10.19.1

A successful exploit could allow the attacker to overwrite arbitrary files on the affected device.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-roomos-trav-beFvCcyu for more information.

    CVEs related to QID 730630

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-roomos-trav-beFvCcyu URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-trav-beFvCcyu