Path traversal in Cisco RoomOS and Cisco TelePresence Collaboration Endpoint (CE) - CVE-2022-20776
Published: October 20, 2022
Vulnerability identifier: #VU68525
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20776
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the video endpoint xAPI. A local administrator can send a specially crafted HTTP request and read and write arbitrary files on the system.
Affected software
Cisco RoomOS
Cisco TelePresence Collaboration Endpoint (CE)
Cisco TelePresence Collaboration Endpoint (CE)
How to mitigate CVE-2022-20776
Install update from vendor's website.
Cisco TelePresence Collaboration Endpoint (CE) - update to 10.20.1