Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrhg-66xp-fmhv

Опубликовано: 15 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device.

This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information. Note: This vulnerability only affects Cisco Webex Desk Hub. There are no workarounds that address this vulnerability.

A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device.

This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information. Note: This vulnerability only affects Cisco Webex Desk Hub. There are no workarounds that address this vulnerability.

EPSS

Процентиль: 26%
0.00089
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 года назад

A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information. Note: This vulnerability only affects Cisco Webex Desk Hub. There are no workarounds that address this vulnerability.

CVSS3: 4.3
fstec
почти 3 года назад

Уязвимость микропрограммного обеспечения устройства управления конференц-связью Cisco TelePresence Collaboration Endpoint (CE) и операционных систем Cisco RoomOS, связанная с недостатками контроля доступа, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 26%
0.00089
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-125