Arbitrary File Overwriting Vulnerabilities in Cisco TelePresence CE and RoomOS
CVE-2023-20093
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 15 November 2024
Summary
This security concern involves multiple vulnerabilities found within the Command-Line Interface (CLI) of Cisco TelePresence CE and RoomOS. These weaknesses stem from insufficient access control mechanisms that allow authenticated local attackers to place symbolic links in specific locations on the local file system. By exploiting these vulnerabilities, an attacker could overwrite arbitrary files, potentially compromising the integrity of the affected device. It is essential for users to be aware that to carry out such attacks, the attacker must possess a remote support user account. Relevant software updates from Cisco aim to mitigate these vulnerabilities, and currently, there are no viable workarounds.
Affected Version(s)
Cisco RoomOS Software
Cisco TelePresence Endpoint Software (TC/CE)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved