Arbitrary File Overwriting Vulnerabilities in Cisco TelePresence CE and RoomOS
CVE-2023-20093

4.4MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
15 November 2024

Summary

This security concern involves multiple vulnerabilities found within the Command-Line Interface (CLI) of Cisco TelePresence CE and RoomOS. These weaknesses stem from insufficient access control mechanisms that allow authenticated local attackers to place symbolic links in specific locations on the local file system. By exploiting these vulnerabilities, an attacker could overwrite arbitrary files, potentially compromising the integrity of the affected device. It is essential for users to be aware that to carry out such attacks, the attacker must possess a remote support user account. Relevant software updates from Cisco aim to mitigate these vulnerabilities, and currently, there are no viable workarounds.

Affected Version(s)

Cisco RoomOS Software

Cisco TelePresence Endpoint Software (TC/CE)

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.