CVE-2022-20768
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to access confidential information, some of which may contain personally identifiable information (PII). Note: To access the logs that are stored in the RoomOS Cloud, an attacker would need valid Administrator-level credentials.
Una vulnerabilidad en el componente de registro de Cisco TelePresence Collaboration Endpoint (CE) y el software RoomOS podría permitir a un atacante remoto autenticado visualizar información confidencial en texto sin cifrar en un sistema afectado. Esta vulnerabilidad es debido al almacenamiento de determinadas credenciales sin cifrar. Un atacante podría explotar esta vulnerabilidad al acceder a los registros de auditoría de un sistema afectado y obteniendo credenciales a las que normalmente no tendría acceso. Un ataque con éxito podría permitir al atacante usar esas credenciales para acceder a información confidencial, algunas de las cuales pueden contener información personal identificable (PII). Nota: Para acceder a los registros que son almacenados en RoomOS Cloud, un atacante necesitaría credenciales válidas de nivel de administrador
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-11-02 CVE Reserved
- 2022-07-06 CVE Published
- 2024-09-27 EPSS Updated
- 2024-11-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Telepresence Collaboration Endpoint Search vendor "Cisco" for product "Telepresence Collaboration Endpoint" | < 10.15.2.2 Search vendor "Cisco" for product "Telepresence Collaboration Endpoint" and version " < 10.15.2.2" | - |
Affected
|