Cisco TelePresence CE and RoomOS Vulnerability: Elevated Privileges for Authenticated Attackers
CVE-2023-20090
6.7MEDIUM
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 15 November 2024
What is CVE-2023-20090?
A security issue exists in Cisco TelePresence CE and RoomOS, which stems from inadequate access control on specific command-line interface (CLI) commands. This vulnerability enables an authenticated, local attacker to execute a series of specially crafted commands that can lead to elevated privileges, potentially allowing the attacker to gain root-level access on the affected devices. Cisco has issued software updates to mitigate this flaw, and there are currently no available workarounds.
Affected Version(s)
Cisco RoomOS Software
Cisco TelePresence Endpoint Software (TC/CE) CE9.10.2
Cisco TelePresence Endpoint Software (TC/CE) CE9.1.4