QID 730699
Date Published: 2023-03-06
QID 730699: Cisco TelePresence Collaboration Endpoint Software Server-Side Request Forgery (SSRF) Vulnerability (cisco-sa-roomos-dkjGFgRK)
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device.
Affected Version:
Cisco TelePresence CE Software Prior to 10.19.2.2
Note: No support for RoomOS software.
QID Detection Logic (Unauthenticated):
The check matches Cisco TelePresence CE Software version retrieved via SNMP Banner.
A successful exploit could allow the attacker to overwrite arbitrary files on the affected device.
Solution
Customers are advised to refer to cisco-sa-roomos-dkjGFgRK for more information.
Vendor References
- cisco-sa-roomos-dkjGFgRK -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK
CVEs related to QID 730699
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-roomos-dkjGFgRK |
|