QID 730698

Date Published: 2023-02-01

QID 730698: Cisco TelePresence Collaboration Endpoint Server-Side Request Forgery (SSRF) Vulnerability (cisco-sa-roomos-dkjGFgRK)

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device.

Affected Version:
Cisco TelePresence CE Software Prior to 10.19.4

Note: No support for RoomOS software.

QID Detection Logic (Unauthenticated):
The check matches Cisco TelePresence CE Software version retrieved via SNMP Banner.

A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected system.

  • CVSS V3 rated as Medium - 4.4 severity.
  • CVSS V2 rated as Medium - 3.2 severity.
  • Solution

    Customers are advised to refer to cisco-sa-roomos-dkjGFgRK for more information.

    CVEs related to QID 730698

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-roomos-dkjGFgRK URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK