QID 730698
Date Published: 2023-02-01
QID 730698: Cisco TelePresence Collaboration Endpoint Server-Side Request Forgery (SSRF) Vulnerability (cisco-sa-roomos-dkjGFgRK)
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device.
Affected Version:
Cisco TelePresence CE Software Prior to 10.19.4
Note: No support for RoomOS software.
QID Detection Logic (Unauthenticated):
The check matches Cisco TelePresence CE Software version retrieved via SNMP Banner.
A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected system.
Solution
Customers are advised to refer to cisco-sa-roomos-dkjGFgRK for more information.
Vendor References
- cisco-sa-roomos-dkjGFgRK -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK
CVEs related to QID 730698
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-roomos-dkjGFgRK |
|