Unauthenticated Attacker could Impersonate Legitimate Device and Pair with Affected Device
CVE-2022-20793
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 15 November 2024
Summary
A flaw in the device pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices exposes a significant security risk. This vulnerability arises from inadequate identity verification, permitting an unauthenticated remote attacker to masquerade as a legitimate device. By responding to the pairing broadcast from an affected device, an attacker could establish a connection, gaining unauthorized access. This exploitation highlights the necessity for robust identity verification mechanisms to safeguard against unauthorized pairing attempts. No workarounds are available to mitigate this issue.
Affected Version(s)
Cisco RoomOS Software
Cisco TelePresence Endpoint Software (TC/CE) CE9.10.2
Cisco TelePresence Endpoint Software (TC/CE) CE9.1.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved