First published: Wed Oct 06 2021(Updated: )
A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient access controls to a shared memory resource. An attacker could exploit this vulnerability by corrupting a shared memory segment on an affected device. A successful exploit could allow the attacker to cause the device to reload. The device will recover from the corruption upon reboot.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Collaboration Endpoint | <10.7.2 | |
Cisco RoomOS | <10.7.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34758 is a vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software.
The severity of CVE-2021-34758 is medium with a severity value of 3.3.
CVE-2021-34758 affects Cisco TelePresence Collaboration Endpoint Software versions up to and excluding 10.7.2.
CVE-2021-34758 affects Cisco RoomOS Software versions up to and excluding 10.7.1.2.
Yes, Cisco has released a security advisory with mitigation details for CVE-2021-34758. Please refer to the reference link for more information.