Unauthorized Access to Sensitive Information on Cisco Webex Desk Hub Devices
CVE-2023-20094
4.3MEDIUM
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 15 November 2024
What is CVE-2023-20094?
A vulnerability exists within Cisco TelePresence CE and RoomOS that permits an unauthenticated, adjacent attacker to access sensitive information stored on affected devices. This issue arises from improper bounds checking in the software. By sending specially crafted requests to these devices, an attacker may exploit this vulnerability to execute an out-of-bounds read, potentially exposing confidential data. Currently, all affected users, particularly those utilizing the Cisco Webex Desk Hub, face significant risks with no available workarounds.
Affected Version(s)
Cisco RoomOS Software
Cisco TelePresence Endpoint Software (TC/CE)