CVE-2021-34758: Cisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service Vulnerability
A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient access controls to a shared memory resource. An attacker could exploit this vulnerability by corrupting a shared memory segment on an affected device. A successful exploit could allow the attacker to cause the device to reload. The device will recover from the corruption upon reboot.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34758?
CVE-2021-34758 is a vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software.
What is the severity of CVE-2021-34758?
The severity of CVE-2021-34758 is medium with a severity value of 3.3.
How does CVE-2021-34758 affect Cisco TelePresence Collaboration Endpoint Software?
CVE-2021-34758 affects Cisco TelePresence Collaboration Endpoint Software versions up to and excluding 10.7.2.
How does CVE-2021-34758 affect Cisco RoomOS Software?
CVE-2021-34758 affects Cisco RoomOS Software versions up to and excluding 10.7.1.2.
Is there a fix available for CVE-2021-34758?
Yes, Cisco has released a security advisory with mitigation details for CVE-2021-34758. Please refer to the reference link for more information.