CWE
59 CWE-918 918
Advisory Published
Updated

cisco-sa-roomos-dkjGFgRK: Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities

First published: Wed Jan 11 2023(Updated: )

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected

Affected SoftwareAffected VersionHow to fix
Cisco TelePresence Collaboration Endpoint Software
Cisco RoomOS Software

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Child vulnerabilities

(Contains the following vulnerabilities)

Frequently Asked Questions

  • What is the severity of cisco-sa-roomos-dkjGFgRK?

    The severity of cisco-sa-roomos-dkjGFgRK is evaluated as high due to the potential for SSRF attacks and file overwriting.

  • How do I fix cisco-sa-roomos-dkjGFgRK?

    To fix cisco-sa-roomos-dkjGFgRK, apply the latest security patches and updates provided by Cisco for affected software versions.

  • What types of attacks can cisco-sa-roomos-dkjGFgRK facilitate?

    cisco-sa-roomos-dkjGFgRK can facilitate server-side request forgery (SSRF) attacks and unauthorized file overwriting on the affected devices.

  • Who is affected by cisco-sa-roomos-dkjGFgRK?

    Cisco TelePresence Collaboration Endpoint and Cisco RoomOS Software users are affected by the vulnerabilities described in cisco-sa-roomos-dkjGFgRK.

  • Is authentication required for exploiting cisco-sa-roomos-dkjGFgRK?

    Yes, exploiting cisco-sa-roomos-dkjGFgRK requires an authenticated, local attacker to access the affected device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203