CVE-2022-20794: Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20794?
CVE-2022-20794 is a vulnerability in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software that could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination.
What software is affected by CVE-2022-20794?
Cisco TelePresence Collaboration Endpoint (CE) Software versions up to 9.15.0.11, Cisco TelePresence Collaboration Endpoint (CE) Software versions between 10.0.0.0 and 10.8.2.5, and Cisco RoomOS versions up to 2021-05 are affected by CVE-2022-20794.
What is the severity of CVE-2022-20794?
CVE-2022-20794 has a severity rating of medium with a CVSS score of 4.7.
How can CVE-2022-20794 be exploited?
CVE-2022-20794 can be exploited by a remote attacker to cause a denial of service (DoS) condition, view sensitive data, or redirect users to an attacker-controlled destination.
Is there a fix for CVE-2022-20794?
Yes, Cisco has released software updates to address the vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software.