Improper access control in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS - CVE-2022-20954
Published: October 20, 2022
Cisco TelePresence Collaboration Endpoint (CE)
Cisco RoomOS
Cisco Systems, Inc
Description
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions on files that are within the local file system. A local administrator can place a symbolic link in a specific location on the local file system and overwrite arbitrary files on the target device.