Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-20094

Опубликовано: 15 нояб. 2024
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device.

This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information. Note: This vulnerability only affects Cisco Webex Desk Hub. There are no workarounds that address this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:telepresence_collaboration_endpoint:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:roomos:-:*:*:*:*:*:*:*

EPSS

Процентиль: 26%
0.00089
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 4.3
github
около 1 года назад

A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information. Note: This vulnerability only affects Cisco Webex Desk Hub. There are no workarounds that address this vulnerability.

CVSS3: 4.3
fstec
почти 3 года назад

Уязвимость микропрограммного обеспечения устройства управления конференц-связью Cisco TelePresence Collaboration Endpoint (CE) и операционных систем Cisco RoomOS, связанная с недостатками контроля доступа, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 26%
0.00089
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-125