Improper access control in Cisco RoomOS and Cisco TelePresence Collaboration Endpoint (CE) - CVE-2023-20008
Published: January 12, 2023
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access controls on files that are in the local file system. A local administrator can place a symbolic link in a specific location on the local file system and overwrite arbitrary files on the target device.
Affected software
Cisco TelePresence Collaboration Endpoint (CE)