Unauthorized Access to Sensitive Information on Cisco Webex Desk Hub Devices
CVE-2023-20094

4.3MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
15 November 2024

Summary

A vulnerability exists within Cisco TelePresence CE and RoomOS that permits an unauthenticated, adjacent attacker to access sensitive information stored on affected devices. This issue arises from improper bounds checking in the software. By sending specially crafted requests to these devices, an attacker may exploit this vulnerability to execute an out-of-bounds read, potentially exposing confidential data. Currently, all affected users, particularly those utilizing the Cisco Webex Desk Hub, face significant risks with no available workarounds.

Affected Version(s)

Cisco RoomOS Software

Cisco TelePresence Endpoint Software (TC/CE)

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.