Cisco TelePresence CE and RoomOS Vulnerability: Elevated Privileges for Authenticated Attackers
CVE-2023-20090

6.7MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
15 November 2024

Summary

A security issue exists in Cisco TelePresence CE and RoomOS, which stems from inadequate access control on specific command-line interface (CLI) commands. This vulnerability enables an authenticated, local attacker to execute a series of specially crafted commands that can lead to elevated privileges, potentially allowing the attacker to gain root-level access on the affected devices. Cisco has issued software updates to mitigate this flaw, and there are currently no available workarounds.

Affected Version(s)

Cisco RoomOS Software

Cisco TelePresence Endpoint Software (TC/CE) CE9.10.2

Cisco TelePresence Endpoint Software (TC/CE) CE9.1.4

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.