QID 730699

Date Published: 2023-03-06

QID 730699: Cisco TelePresence Collaboration Endpoint Software Server-Side Request Forgery (SSRF) Vulnerability (cisco-sa-roomos-dkjGFgRK)

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device.

Affected Version:
Cisco TelePresence CE Software Prior to 10.19.2.2

Note: No support for RoomOS software.

QID Detection Logic (Unauthenticated):
The check matches Cisco TelePresence CE Software version retrieved via SNMP Banner.

A successful exploit could allow the attacker to overwrite arbitrary files on the affected device.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to cisco-sa-roomos-dkjGFgRK for more information.

    CVEs related to QID 730699

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-roomos-dkjGFgRK URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK