Local File Overwrite Vulnerability in Cisco TelePresence CE and RoomOS Software
CVE-2023-20008

7.1HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
20 January 2023

Summary

A local file overwrite vulnerability exists in the CLI of Cisco TelePresence CE and RoomOS Software. It arises due to inadequate access controls on files in the local file system. An authenticated attacker with local access can exploit this vulnerability by creating a symbolic link in a specific directory on the device's local file system. This exploit can lead to the unintended overwriting of arbitrary files, potentially compromising the integrity of the affected system.

Affected Version(s)

Cisco RoomOS Software RoomOS 10.3.2.0

Cisco RoomOS Software RoomOS 10.3.4.0

Cisco RoomOS Software RoomOS 10.8.2.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.