Path traversal in Cisco RoomOS and Cisco TelePresence Collaboration Endpoint (CE) - CVE-2022-20811
Published: October 20, 2022
Vulnerability identifier: #VU68537
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20811
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the video endpoint xAPI. A remote administrator can send a specially crafted HTTP request and read and write arbitrary files on the system.
Affected software
Cisco RoomOS
Cisco TelePresence Collaboration Endpoint (CE)
Cisco TelePresence Collaboration Endpoint (CE)
How to mitigate CVE-2022-20811
Install update from vendor's website.
Cisco TelePresence Collaboration Endpoint (CE) - addressed in versions 9.15.13.0, 10.15.2.2