A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device.
This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information.
Note: This vulnerability only affects Cisco Webex Desk Hub.
There are no workarounds that address this vulnerability.
References
Link | Resource |
---|---|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-file-write-rHKwegKf | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
30 Jul 2025, 17:19
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:cisco:roomos:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:telepresence_collaboration_endpoint:-:*:*:*:*:*:*:* |
|
References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-file-write-rHKwegKf - Vendor Advisory | |
First Time |
Cisco
Cisco roomos Cisco telepresence Collaboration Endpoint |
18 Nov 2024, 17:11
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Nov 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-15 16:15
Updated : 2025-07-30 17:19
NVD link : CVE-2023-20094
Mitre link : CVE-2023-20094
CVE.ORG link : CVE-2023-20094
JSON object : View
Products Affected
cisco
- roomos
- telepresence_collaboration_endpoint
CWE
CWE-125
Out-of-bounds Read